PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the kfm_base_path parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.071
EPSS Ranking 91.1%