First published: Tue Oct 30 2018(Updated: )
An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mingsoft MCMS | =4.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18831 is a vulnerability discovered in MCMS 4.6.5 that allows an attacker to write a .jsp file to an arbitrary directory through a ../ Directory Traversal in the url parameter.
An attacker can exploit CVE-2018-18831 by writing a .jsp file in the position parameter and exploiting the ../ Directory Traversal vulnerability in the url parameter.
The severity of CVE-2018-18831 is high, with a CVSS score of 7.5.
To fix CVE-2018-18831, it is recommended to update MCMS to a version that addresses the vulnerability.
You can find more information about CVE-2018-18831 at the following URL: https://gitee.com/mingSoft/MCMS/issues/IO0K0