An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.
| Software | From | Fixed in |
|---|---|---|
| publiccms / publiccms | 4.0.202406.f | 4.0.202406.f.x |