CVE-2018-10235
POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diymodulemembercontrollersadminSetting.php ‘index’ function because an attacker can control the value of $cache[‘setting’][‘ucssocfg’] in diymodulemembermodelsMember_model.php and write this code into the api/ucsso/config.php file.
Date published : 2018-04-19
https://github.com/myndtt/vulnerability/blob/master/poscms/3-2-10.md