CVE-2025-29287: Malicious File Upload
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/net.mingsoft:ms-mcmsto a version that resolves this vulnerability.Fixed in 5.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29287?
CVE-2025-29287 is classified as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2025-29287?
To fix CVE-2025-29287, update the ueditor component of MCMS to the latest version that addresses this vulnerability.
What systems are affected by CVE-2025-29287?
CVE-2025-29287 affects the ueditor component in MCMS version 5.4.3.
What attack vectors are associated with CVE-2025-29287?
CVE-2025-29287 allows attackers to exploit the vulnerability by uploading crafted files to execute arbitrary code.
Can CVE-2025-29287 be exploited remotely?
Yes, CVE-2025-29287 can be exploited remotely due to the nature of the arbitrary file upload vulnerability.