An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://semcms.com | product |
http://www.sem-cms.com/ | product |
https://gitee.com/whats-the-bad-idea/cve | broken link |