KuaiFanCMS V5.x contains an arbitrary file read vulnerability in the html_url parameter of the chakanhtml.module.php file.
- https://github.com/poropro/kuaifan/issues/3
No PoCs found on GitHub currently.