
Proof-of-concept exploit for CVE-2024-31666 enabling remote code execution in Flusity-CMS v2.33 via crafted script in edit_addon_post.php component.
A vulnerability exists in Flusity-CMS v.2.33 that allows a remote attacker to execute arbitrary code via a crafted script in the edit_addon_post.php component.
An attacker can exploit this vulnerability by sending a crafted script to the edit_addon_post.php component, thereby executing arbitrary code on the target server.
This vulnerability may allow an attacker to execute arbitrary code on the server, potentially gaining full control over the server.