The fetch and display functions in the HomeBaseController class(parent class of IndexController) and AdminbaseController class are assigned as public so that they can be accessed easily from outside. A remote attacker can use this vulnerability to construct a malicious URL and write files of arbitrary content to the server without any permission to achieve the purpose of remote code execution.
ThinkCMF X1.6.0,ThinkCMF X2.1.0,ThinkCMF X2.2.0,ThinkCMF X2.2.1,ThinkCMF X2.2.2ThinkCMF X2.2.3