[CVE ID]
CVE-2024-48180
[PRODUCT]
ClassCMS
[VERSION]
ClassCMS <=4.8
[VulnerabilityType Other]
file inclusion
[Vendor of Product]
https://classcms.com/
[Affected Component]
There is a file inclusion vulnerability in the nowView method in/class/cms/cms.php, which can include a txt file uploaded to the/class/template directory to execute PHP code
[Attack Type]
Remote
[4.0K] /data/pocs/48d62f522bfba5dd7b3851206bc278575a9e642e
├── [507K] cms.pdf
└── [ 367] README.md
0 directories, 2 files