First published: Mon Apr 21 2025(Updated: )
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/net.mingsoft:ms-mcms | <5.4.4 | 5.4.4 |
百度 UEditor | ||
Mingsoft MCMS | =5.4.3 | |
=5.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29287 is classified as a critical vulnerability due to the potential for arbitrary code execution.
To fix CVE-2025-29287, update the ueditor component of MCMS to the latest version that addresses this vulnerability.
CVE-2025-29287 affects the ueditor component in MCMS version 5.4.3.
CVE-2025-29287 allows attackers to exploit the vulnerability by uploading crafted files to execute arbitrary code.
Yes, CVE-2025-29287 can be exploited remotely due to the nature of the arbitrary file upload vulnerability.