EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
https://github.com/eyoucms/eyoucms/issues/22 | third party advisory exploit |
https://www.eyoucms.com/rizhi/ | release notes vendor advisory |