MCMS Arbitrary File Upload Vulnerability in Ueditor Component

Vulnerability

A vulnerability allowing arbitrary file upload has been identified in the ueditor component of MCMS version 5.4.3. This issue enables attackers to upload crafted files that could execute arbitrary code, potentially leading to malicious effects on the user.

Impact

Exploitation of this vulnerability could result in unauthorized code execution on the server where MCMS is hosted.

Reproduction

The vulnerability can be reproduced by uploading a malicious file through the ueditor component while editing in the editor. This action bypasses file upload restrictions and allows the execution of arbitrary code.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
6.8
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.