Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Link | Tags |
---|---|
https://github.com/hansmach1ne/MyExploits/tree/main/LFI_in_CuppaCMS_templates | third party advisory exploit |
https://github.com/CuppaCMS/CuppaCMS/issues/18 | third party advisory exploit |