PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.164
EPSS Ranking 94.6%