CVE-2022-47042: Malicious File Upload
Published Jan 24, 2023
·Updated
MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.
Affected Software
3 affected components
Mingsoft MCMS=5.2.8
Mingsoft MCMS=5.2.9
Mingsoft MCMS=5.2.10
Event History
Jan 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-47042?
CVE-2022-47042 is an arbitrary file write vulnerability in MCMS v5.2.10 and below via the component ms/template/writeFileContent.do.
2
How severe is CVE-2022-47042?
CVE-2022-47042 has a severity level of 8.8 (high).
3
Which software versions are affected by CVE-2022-47042?
Versions 5.2.8, 5.2.9, and 5.2.10 of Mingsoft MCMS are affected by CVE-2022-47042.
4
How can I fix CVE-2022-47042?
To fix CVE-2022-47042, update your MCMS software to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2022-47042?
More information about CVE-2022-47042 can be found at the following reference: https://gitee.com/mingSoft/MCMS/issues/I6592F