A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function
add/edit
of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection.
This vulnerability is traded as CVE-2024-10505. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
Initially two separate issues were created by the researcher for the different function calls.