An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.
No PoCs from references.
- https://github.com/izj007/wechat
- https://github.com/whoami13apt/files2