PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java.
Link | Tags |
---|---|
https://github.com/JinYiTong/CVE-Req/blob/main/publiccms/publiccms.md | third party advisory exploit |
https://github.com/sanluan/PublicCMS/commit/d8d7626cf51e4968fb384e1637a3c0c9921f33e9 | third party advisory patch |