CVE-2021-46386

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
26/01/2022
Last modified:
21/11/2022

Description

File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mingsoft:mcms:*:*:*:*:*:*:*:* 5.2.5 (including)


References to Advisories, Solutions, and Tools