An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by directly accessing the website built by UCMS.
No PoCs from references.
- https://github.com/404notf0und/CVE-Flow