LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://igml.top/2021/05/10/lightcms-RCE/ | third party advisory exploit |
https://github.com/eddy8/LightCMS/issues/21 | issue tracking exploit patch |