mapFiler.php in Mapbender 2.4 to 2.4.4 allows remote attackers to execute arbitrary PHP code via PHP code sequences in the factor parameter, which are not properly handled when accessing a filename that contains those sequences.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.043
EPSS Ranking 88.5%