CRITICAL9.8
GHSA-6vf2-mfmr-qqqw
Liufee CMS File Upload vulnerability
Quick fix
GHSA-6vf2-mfmr-qqqw — feehi/cms: upgrade to the fixed version with the command below.
composer require feehi/cms:^2.0.8.1Details
File Upload vulnerability in Liufee CMS, AKA Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the `/admin/index.php?r=admin-user%2Fupdate-self` component.
Are you affected?
Enter the version of the package you're using.