CVE-2019-17370: Otcms
High severity, CVSS 7.2. EPSS: 2.1% chance of exploitation in the next 30 days.
OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the attacker can create a .php file.
Affected products
- Otcms Otcms: version 3.85 only
Published 2019-10-09. Last modified 2026-06-17.