An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.045
EPSS Ranking 88.8%