CVE-2022-22929: Malicious File Upload
Published Jan 20, 2022
·Updated
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.
Affected Software
1 affected component
Mingsoft MCMS=5.2.4
Event History
Jan 20, 2022
CVE Published
via MITRE·11:40 PM
Data Sourced
via MITRE·11:40 PM
Description
Frequently Asked Questions
1
What is CVE-2022-22929?
CVE-2022-22929 is an arbitrary file upload vulnerability in MCMS v5.2.4.
2
How can attackers exploit CVE-2022-22929?
Attackers can exploit CVE-2022-22929 by uploading a crafted ZIP file, which allows them to execute arbitrary code.
3
What is the severity of CVE-2022-22929?
CVE-2022-22929 has a severity rating of 9.8, which is considered critical.
4
Which version of MCMS is affected by CVE-2022-22929?
MCMS version 5.2.4 is affected by CVE-2022-22929.
5
How can I fix CVE-2022-22929?
To fix CVE-2022-22929, it is recommended to update the MCMS software to a version that is not affected by the vulnerability.