Publiccms · Publiccms · CVE-2023-48204
**Name of the Vulnerable Software and Affected Versions**
PublicCMS version 4.0.202302.e
**Description**
The issue allows a remote attacker to obtain sensitive information via the `appToken` and `Parameters` parameter of the "api/method/getHtml" component.
**Recommendations**
For PublicCMS version 4.0.202302.e, as a temporary workaround, consider restricting access to the "api/method/getHtml" component until a patch is available. Avoid using the `appToken` and `Parameters` parameters in this component to minimize the risk of exploitation.