uWSGI PHP Plugin before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the –php-docroot option, making it susceptible to local file inclusion.
View the template here CVE-2018-7490.yaml
References:
https://uwsgi-docs.readthedocs.io/en/latest/Changelog-2.0.17.html