SoyCMS 3.0.2 and earlier is affected by Reflected Cross-Site Scripting (XSS) which leads to Remote Code Execution (RCE) from a known vulnerability. This allows remote attackers to force the administrator to edit files once the adminsitrator loads a specially crafted webpage.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:soycms_project:soycms:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"extracted_events": [
{
"last_affected": "3.0.2"
}
],
"vendor_product": "soycms_project:soycms"
}
]
}