CVE-2022-30506: Malicious File Upload
Published May 27, 2022
·Updated
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.
Affected Software
1 affected component
Mingsoft MCMS=5.2.7
Event History
May 27, 2022
CVE Published
via MITRE·01:27 PM
Data Sourced
via MITRE·01:27 PM
Description
Frequently Asked Questions
1
What is CVE-2022-30506?
CVE-2022-30506 is an arbitrary file upload vulnerability in MCMS 5.2.7.
2
How severe is CVE-2022-30506?
CVE-2022-30506 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2022-30506 affect MCMS 5.2.7?
CVE-2022-30506 allows an attacker to execute arbitrary code through a crafted ZIP file in MCMS 5.2.7.
4
What is the CWE category of CVE-2022-30506?
CVE-2022-30506 is categorized as CWE-434, which is an Unrestricted Upload of File with Dangerous Type vulnerability.
5
Is there a fix for CVE-2022-30506?
To fix CVE-2022-30506, it is recommended to update MCMS to a version that addresses the vulnerability.