CVE-2024-10505 | wuzhicms 4.1.0 block.php add/edit code injection
A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection.
This vulnerability is traded as CVE-2024-10505. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
Initially two separate issues were created by the researcher for the different function calls.