EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
No PoCs from references.
- https://github.com/SexyBeast233/SecBooks
- https://github.com/ngostuan/CTF