CVE-2019-17370: Otcms

High severity, CVSS 7.2. EPSS: 2.1% chance of exploitation in the next 30 days.

OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the attacker can create a .php file.

Affected products

  • Otcms Otcms: version 3.85 only

Published 2019-10-09. Last modified 2026-06-17.