CVE-2021-46062: Path Traversal
net.mingsoft:ms-basic is used for plugin management for applications built with Maven for the Mingfei Content Management System (MCMS). ms-basic before 2.1.16 is vulnerable to arbitrary file deletion using POST requests to /template/writeFileContent via the oldFileName parameter. MCMS before 5.2.11 is also vulnerable since it bundles vulnerable versions of ms-basic.
Other sources
MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-46062?
CVE-2021-46062 is a vulnerability in MCMS v5.2.5 that allows arbitrary file deletion via the component old.
How severe is CVE-2021-46062?
CVE-2021-46062 has a severity rating of 7.1 (high).
Which software versions are affected by CVE-2021-46062?
MCMS v5.2.5, net.mingsoft:ms-mcms up to version 5.2.11, and net.mingsoft:ms-basic up to version 2.1.16 are affected by CVE-2021-46062.
How can I fix CVE-2021-46062?
To fix CVE-2021-46062, update MCMS to version 5.2.11, net.mingsoft:ms-mcms to version 5.2.11, and net.mingsoft:ms-basic to version 2.1.16.
Where can I find more information about CVE-2021-46062?
You can find more information about CVE-2021-46062 on the NIST NVD website and the GitHub advisory page.