Launchpad.net

CVE 2019-16657

TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/.

See the CVE page on Mitre.org for more details.

References