CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from /api/index.php.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Cuppacms |
Cuppacms |
1.0 (including) |
1.0 (including) |
References