← Back to CVE List
CVE-2017-11201
application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt