A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a crafted request sent to the server via the 'Create a New Setting' function.
{ "versions": [ { "introduced": "0" }, { "last_affected": "4.4.10" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-26670.json"