CVE-2018-10236: Poscms
High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.
POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function because an attacker can control the value of $data['name'] with no restrictions, and this value is written to the FCPATH.$file file.
Affected products
- Poscms Poscms: version 3.2.18 only
Published 2018-04-19. Last modified 2026-06-17.