S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.
- https://github.com/superjock1988/debug/blob/main/s-cms_rce.md
No PoCs found on GitHub currently.