CVE-2026-2666: mingSoft MCMS Template Archive uploadTemplate.do unrestricted upload
A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2666?
CVE-2026-2666 is considered to have a high severity due to its potential for remote exploitation leading to unrestricted file uploads.
How do I fix CVE-2026-2666?
To mitigate CVE-2026-2666, users should update to the latest version of mingSoft MCMS that addresses this vulnerability.
What component is affected by CVE-2026-2666?
The affected component in CVE-2026-2666 is the Template Archive Handler found in the file /ms/file/uploadTemplate.do.
Can CVE-2026-2666 be exploited remotely?
Yes, CVE-2026-2666 can be exploited remotely, allowing attackers to manipulate the file upload functionality.
What does CVE-2026-2666 allow attackers to do?
CVE-2026-2666 allows attackers to perform unrestricted uploads of files, which can lead to further exploitation of the system.