Security Advisory

CVE-2018-9847

9.8
CRITICAL

Vulnerability Description

In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.
Published Date April 7, 2018
Official Source NIST NVD Advisory