CVE-2018-10235: Poscms
High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.
POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function because an attacker can control the value of $cache['setting']['ucssocfg'] in diy\module\member\models\Member_model.php and write this code into the api/ucsso/config.php file.
Affected products
- Poscms Poscms: version 3.2.10 only
Published 2018-04-19. Last modified 2026-06-17.