CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from /api/index.php.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Cuppacms | Cuppacms | 1.0 (including) | 1.0 (including) |
References