Impact
FastCMS versions earlier than 0.1.6 contain a flaw in the PluginController.java module that permits a local attacker to inject and execute arbitrary code. This weakness matches CWE-94, a code‑injection vulnerability, and can allow an attacker with local access to run arbitrary commands, potentially compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects FastCMS by Xjd2020. All releases prior to 0.1.6 are impacted; no other vendors or products are listed in the CNA data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS of less than 1% suggests a low likelihood of exploitation in the wild. Because the flaw requires local access, remote attackers cannot directly exploit it. It is not listed in the CISA KEV catalog.
OpenCVE Enrichment