Melis Technology Melis Platform Melis Cms Slider Module File Upload Leading to Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in the 'melis-cms-slider' module of Melis Technology's Melis Platform, affecting versions prior to 5.3.1. This vulnerability allows attackers to upload malicious files via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm', using the 'mcsdetail_img' parameter.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where the Melis Platform is hosted.

Remediation

Users can upgrade to Melis Platform version 5.3.1 or later to address this vulnerability.

Added: Oct 8, 2025, 11:18 AM
Updated: Oct 8, 2025, 11:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.