PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.103
EPSS Ranking 92.8%