OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or PASSWORD variables to the backupDB.bat file.
| Software | From | Fixed in |
|---|---|---|
| publiccms / publiccms | 5.202506.a | 5.202506.a.x |
| publiccms / publiccms | 5.202506.b | 5.202506.b.x |