application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
finecms project finecms - |