CVE-2018-10235

POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diymodulemembercontrollersadminSetting.php 'index' function because an attacker can control the value of $cache['setting']['ucssocfg'] in diymodulemembermodelsMember_model.php and write this code into the api/ucsso/config.php file.
References
Configurations

Configuration 1

cpe:2.3:a:poscms:poscms:3.2.10:*:*:*:*:*:*:*

Information

Published : 2018-04-19 06:29

Updated : 2018-05-22 05:10


NVD link : CVE-2018-10235

Mitre link : CVE-2018-10235

Products Affected
No products.
CWE