CVE 2019-16657
TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/
See the
CVE page on Mitre.org
for more details.
TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/