HIGH7.8
GHSA-h92m-4g9m-72vr
juzawebCMS Injection vulnerability
Details
An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/juzaweb/cms
Introduced in:
0No fixed version published yet for juzaweb/cms (composer). Pin to a known-safe version or switch to an alternative.