https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: File Upload. The impact is: execute arbitrary code (remote). The component is: net.mingsoft.basic.action.web.FileAction#upload. The attack vector is: jspx webshell. ΒΆΒΆ MCMS has a file upload vulnerability through which attacker can upload a webshell. Successful attacks of this vulnerability can result in takeover of MCMS
References
| Link | Resource |
|---|---|
| https://gitee.com/mingSoft/MCMS/issues/I4R0GW | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-01-26 17:15
Updated : 2022-02-02 20:50
NVD link : CVE-2021-46386
Mitre link : CVE-2021-46386
JSON object : View
Products Affected
mingsoft
- mcms
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
