MingSoft MCMS
cpe:2.3:a:mingsoft:mcms:*:*:*:*:*:*:*
- 5.4.3
A vulnerability allowing arbitrary file upload has been identified in the ueditor component of MCMS version 5.4.3. This issue enables attackers to upload crafted files that could execute arbitrary code, potentially leading to malicious effects on the user.
Exploitation of this vulnerability could result in unauthorized code execution on the server where MCMS is hosted.
The vulnerability can be reproduced by uploading a malicious file through the ueditor component while editing in the editor. This action bypasses file upload restrictions and allows the execution of arbitrary code.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.