1.Login to the backstage as the administrator.
2.You need to edit the tpl file

- Because the default safe mode configuration is off,so you can edit tpl file to getshell。
The vulnerability code is as follows:

- Add you webshell code in tpl file.

- Then you can getshell in index file.

Repair suggestion:
1、Set safe mode true by default.