In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.
- https://github.com/magicblack/maccms10/issues/747
- https://github.com/ndouglas-cloudsmith/exploit-check