First published: Fri Feb 18 2022(Updated: )
`net.mingsoft:ms-basic` is used for plugin management for applications built with Maven for the [Mingfei Content Management System (MCMS)](https://gitee.com/mingSoft/MCMS). ms-basic before 2.1.16 is vulnerable to arbitrary file deletion using POST requests to `/template/writeFileContent` via the `oldFileName` parameter. MCMS before 5.2.11 is also vulnerable since it bundles vulnerable versions of ms-basic.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/net.mingsoft:ms-mcms | <5.2.11 | 5.2.11 |
maven/net.mingsoft:ms-basic | <2.1.16 | 2.1.16 |
Mingsoft MCMS | =5.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46062 is a vulnerability in MCMS v5.2.5 that allows arbitrary file deletion via the component old.
CVE-2021-46062 has a severity rating of 7.1 (high).
MCMS v5.2.5, net.mingsoft:ms-mcms up to version 5.2.11, and net.mingsoft:ms-basic up to version 2.1.16 are affected by CVE-2021-46062.
To fix CVE-2021-46062, update MCMS to version 5.2.11, net.mingsoft:ms-mcms to version 5.2.11, and net.mingsoft:ms-basic to version 2.1.16.
You can find more information about CVE-2021-46062 on the NIST NVD website and the GitHub advisory page.