PilusCart versions 1.4.1 and prior suffer from a file disclosure vulnerability via local file inclusion.
View the template here CVE-2019-16123.yaml
echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-16123.yaml
References: