CVE-2024-22567: Malicious File Upload
Published Feb 5, 2024
·Updated
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
Affected Software
2 affected components
maven/net.mingsoft:ms-mcms<=5.3.5
Mingsoft MCMS=5.3.5
Event History
Feb 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-22567?
CVE-2024-22567 has been categorized as a high severity vulnerability due to the ability for attackers to upload arbitrary files.
2
How do I fix CVE-2024-22567?
To fix CVE-2024-22567, it is recommended to upgrade MCMS to a version higher than 5.3.5 which addresses this vulnerability.
3
What is the impact of CVE-2024-22567?
The impact of CVE-2024-22567 includes the potential for attackers to execute arbitrary code on the server by uploading malicious files.
4
Is CVE-2024-22567 present in earlier versions of MCMS?
Yes, CVE-2024-22567 affects MCMS version 5.3.5 and potentially earlier versions.
5
What actions should be taken if CVE-2024-22567 is detected?
If CVE-2024-22567 is detected, organizations should immediately apply the recommended updates and review their security measures.