CVE-2021-46386: Malicious File Upload
Published Jan 26, 2022
·Updated
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
Affected Software
1 affected component
Mingsoft MCMS<=5.2.5
Event History
Jan 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this file upload vulnerability?
The vulnerability ID for this file upload vulnerability is CVE-2021-46386.
2
How does this file upload vulnerability in mingSoft MCMS through 5.2.5 occur?
This file upload vulnerability occurs when remote attackers upload a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
3
What is the severity level of CVE-2021-46386?
The severity level of CVE-2021-46386 is critical with a score of 9.8.
4
Which software version is affected by this file upload vulnerability?
The file upload vulnerability affects mingSoft MCMS versions up to and including 5.2.5.
5
How can a remote attacker exploit this file upload vulnerability?
A remote attacker can exploit this file upload vulnerability by uploading a specially crafted jspx webshell.