MRCMS
cpe:2.3:a:mrcms:mrcms:*:*:*:*:*:*:*
- 3.1.2
An arbitrary file upload vulnerability has been identified in MRCMS version 3.1.2, specifically in the component '/file/savefile.do'. This vulnerability allows attackers to execute arbitrary code by uploading a crafted .jsp file. Although the system initially restricts .jsp file uploads, this limitation can be bypassed by using other file extensions, such as .jspx. Once the file is uploaded, the malicious code can be executed, leading to potential exploitation of the application.
Exploitation of this vulnerability allows for arbitrary code execution on the server where MRCMS is hosted.
To reproduce this vulnerability, upload a file with a .jspx extension through the '/file/savefile.do' endpoint. The system's restriction on .jsp files can be bypassed by using this alternative extension, allowing the upload of a file that could execute arbitrary code on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.