CRITICAL9.8
GHSA-q3q5-qvh5-cmw5
liufee CMS File Upload vulnerability
Quick fix
GHSA-q3q5-qvh5-cmw5 — feehi/cms: upgrade to the fixed version with the command below.
composer require feehi/cms:^2.0.8.1Details
File Upload vulnerability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
Are you affected?
Enter the version of the package you're using.