In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.
- https://blog.csdn.net/qq_41770175/article/details/93486383
No PoCs found on GitHub currently.