74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://github.com/N1ce759/74cmsSE-Arbitrary-File-Reading/issues/1 | issue tracking exploit third party advisory |