PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.03
EPSS Ranking 85.7%