daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.
CVSS Metrics