Vulnerabilities (CVE)

Filtered by vendor Phpkaiyuancms Subscribe
Filtered by product Phpopensourcecms
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-16278 1 Phpkaiyuancms 1 Phpopensourcecms 2023-12-10 7.5 HIGH 9.8 CRITICAL
phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter.