CVE-2017-11178: Finecms Project Finecms
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
In FineCMS through 2017-07-11, application/core/controller/style.php allows remote attackers to write to arbitrary files via the contents and filename parameters in a route=style action. For example, this can be used to overwrite a .php file because the file extension is not checked.
Affected products
- Finecms Project Finecms: up to and including 2017-05-12
Published 2017-07-12. Last modified 2026-06-17.