Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.444
EPSS Ranking 98.6%