Security Advisory
CVE-2018-9847
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
In Gxlcms QY v1.0.0713, the update function in LibLibActionAdminTplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.