An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20294
Reference (s):
- https://github.com/arterli/CmsWing/issues/49