Mingsoft MCMS vulnerable to Remote Code Execution via file upload.
Critical severity
GitHub Reviewed
Published
Jan 27, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jan 26, 2022
Published to the GitHub Advisory Database
Jan 27, 2022
Reviewed
Oct 25, 2022
Last updated
Jan 29, 2023
Mingsoft MCMS is a Java CMS. Versions prior to and including 5.2.5 contain a file upload vulnerability allowing for a jspx webshell to be uploaded via net.mingsoft.basic.action.web.FileAction#upload, resulting in remote code execution. It is unclear if this issue has been patched.
References