An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php.
- https://github.com/pcmt/superMicro-CMS/issues/2
- https://github.com/fkie-cad/nvd-json-data-feeds