RiteCMS v3.1.0 contains an authenticated Remote Code Execution (RCE) vulnerability via its content_function() handler. The vulnerability allows users with page-editing privileges to execute arbitrary PHP code on the server by injecting [function:...] tags into page content.
| Vendor | Product | Versions |
|---|---|---|
| handylulu | ritecms | 3.1.0 |