FineCMS through 5.0.10 contains a cross-site scripting vulnerability in controllers/api.php via the function parameter in a c=api&m=data2 request.
id: CVE-2017-11629
info:
name: FineCMS <=5.0.10 - Cross-Site Scripting
author: ritikchaddha
s
...