An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
- https://github.com/taogogo/taocms/issues/34
- https://github.com/taogogo/taocms/issues/34?by=xboy%28topsec%29
- https://github.com/taogogo/taocms/issues/34?by=xboy(topsec)
No PoCs found on GitHub currently.