CVE-2021-46384: Critical severity mcms vulnerability
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to compromise MCMS. Successful attacks of this vulnerability can result in takeover of MCMS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-46384?
CVE-2021-46384 is a critical vulnerability in MCMS <=5.2.5 that allows an unauthenticated attacker to execute arbitrary code remotely.
What is the impact of CVE-2021-46384?
The impact of CVE-2021-46384 is the ability for an attacker to execute arbitrary code remotely.
What is the attack vector for CVE-2021-46384?
The attack vector for CVE-2021-46384 is using the "freemarker.template.utility.Execute" function to execute arbitrary code.
How severe is CVE-2021-46384?
CVE-2021-46384 has a severity rating of 9.8, which is classified as critical.
How can I fix CVE-2021-46384?
To fix CVE-2021-46384, update MCMS to a version higher than 5.2.5.