CVE-2020-22755: Malicious File Upload
Published May 8, 2023
·Updated
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.
Affected Software
2 affected components
maven/net.mingsoft:ms-mcms<=5.0.0
Mingsoft MCMS=5.0
Event History
May 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is CVE-2020-22755?
CVE-2020-22755 is a file upload vulnerability in MCMS 5.0 that allows attackers to execute arbitrary code via a crafted thumbnail.
2
How does CVE-2020-22755 impact users?
CVE-2020-22755 has a severity keyword of 'high' with a severity value of 8.8, indicating a significant security risk.
3
What software versions are affected by CVE-2020-22755?
MCMS 5.0 and net.mingsoft:ms-mcms version 5.0.0 are affected by CVE-2020-22755.
4
How can an attacker exploit CVE-2020-22755?
An attacker can exploit CVE-2020-22755 by uploading a specially crafted thumbnail file to execute arbitrary code.
5
Are there any fixes or patches available for CVE-2020-22755?
It is recommended to update MCMS to a version that has addressed CVE-2020-22755. Check the official MCMS website or Maven repository for patched versions.