CVE-2021-46386

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 7.5 (High)
75% Progress
EPSS 0.75 % (81th)
0.75% Progress
Affected Products 1
Advisories 1

File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.

Weaknesses
CWE-434
Unrestricted Upload of File with Dangerous Type
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2022-01-26 17:15:07
(2 years ago)
Updated Date
2022-11-21 19:45:19
(22 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mingsoft Mcms 5.2.5 and prior versions cpe:2.3:a:mingsoft:mcms <= 5.2.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...