publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://gitee.com/sanluan/PublicCMS/issues/IADVDM | issue tracking exploit |
https://gist.github.com/ilikeoyt/3dbbca2679c2551eaaeaea9c83acf1a1 | third party advisory |