ClassCMS v4.8 has a code execution vulnerability....
Critical severity
Unreviewed
Published
Feb 3, 2025
to the GitHub Advisory Database
•
Updated Feb 4, 2025
Description
Published by the National Vulnerability Database
Feb 3, 2025
Published to the GitHub Advisory Database
Feb 3, 2025
Last updated
Feb 4, 2025
ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server.
References