CVE-2022-22930
https://notcve.org/view.php?id=CVE-2022-22930
20 Jan 2022 — A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload. Una vulnerabilidad de ejecución de código remota (RCE) en la función Template Management de MCMS versión v5.2.4, permite a atacantes ejecutar código arbitrario por medio de una carga útil diseñada • https://gitee.com/mingSoft/MCMS/issues/I4Q4M6 •
CVE-2022-23314
https://notcve.org/view.php?id=CVE-2022-23314
20 Jan 2022 — MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do. Se ha detectado que MCMS versión v5.2.4, contiene una vulnerabilidad de inyección SQL por medio del archivo /ms/mdiy/model/importJson.do • https://gitee.com/mingSoft/MCMS/issues/I4Q4OT • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-23315
https://notcve.org/view.php?id=CVE-2022-23315
20 Jan 2022 — MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do. Se ha detectado que MCMS versión v5.2.4, contiene una vulnerabilidad de carga de archivos arbitraria por medio del componente /ms/template/writeFileContent.do • https://gitee.com/mingSoft/MCMS/issues/I4Q4PX • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2022-22929
https://notcve.org/view.php?id=CVE-2022-22929
20 Jan 2022 — MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file. Se ha detectado que MCMS versión v5.2.4, presenta una vulnerabilidad de carga de archivos arbitrarios en el módulo New Template, que permite a atacantes ejecutar código arbitrario por medio de un archivo ZIP diseñado • https://gitee.com/mingSoft/MCMS/issues/I4Q4NV • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2022-22928
https://notcve.org/view.php?id=CVE-2022-22928
20 Jan 2022 — MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code. Se ha detectado que MCMS versión v5.2.4, presenta una clave shiro embebida, que permite a atacantes explotar la clave y ejecutar código arbitrario • https://gitee.com/mingSoft/MCMS/issues/I4Q4RP • CWE-798: Use of Hard-coded Credentials •
CVE-2020-23262
https://notcve.org/view.php?id=CVE-2020-23262
22 Jan 2021 — An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do. Se detectó un problema en ming-soft MCMS versión v5.0, donde un usuario malicioso puede explotar una inyección SQL sin iniciar sesión por medio del archivo /mcms/view.do • https://github.com/ming-soft/MCMS/issues/45 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2018-18831
https://notcve.org/view.php?id=CVE-2018-18831
30 Oct 2018 — An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter. Se ha descubierto un problema en com\mingsoft\cms\action\GeneraterAction.java en MCMS 4.6.5. Un atacante puede escribir un archivo .jsp (en el parámetro position) a un directorio arbitrario mediante un ../ (salto de directorio) en el parámetro url. • https://gitee.com/mingSoft/MCMS/issues/IO0K0 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2018-18830
https://notcve.org/view.php?id=CVE-2018-18830
30 Oct 2018 — An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename, and then intercept the data packet. In the name parameter, change the suffix to jsp. In the response, the server returns the storage path of the file, which can be accessed to execute arbitrary JSP code. • https://gitee.com/mingSoft/MCMS/issues/IO0IQ • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2018-17366
https://notcve.org/view.php?id=CVE-2018-17366
23 Sep 2018 — An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. Se ha descubierto un problema en MCMS 4.6.5. Existe una vulnerabilidad Cross-Site Request Forgery (CSRF) que puede añadir una cuenta administrador a través de /index.php/admin/admin_manage/add.html. • https://gitee.com/mingSoft/MCMS/issues/IM1DA • CWE-352: Cross-Site Request Forgery (CSRF) •