classcms < 2.5 - Arbitrary File Upload and Remote Code Execution via Crafted .txt File
Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.