CVE-2019-11377: Wcms
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according to the fm_get_text_exts function.
Affected products
- Wcms Wcms: version 0.3.2 only
Published 2019-04-20. Last modified 2026-06-17.