https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to compromise MCMS. Successful attacks of this vulnerability can result in takeover of MCMS.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1523 | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to compromise MCMS. Successful attacks of this vulnerability can result in takeover of MCMS. |
Github GHSA |
GHSA-qwh6-xwj4-9cjg | Remote code execution in net.mingsoft:ms-mcms |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://gitee.com/mingSoft/MCMS/issues/I4QZ1O |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T05:02:11.602Z
Reserved: 2022-01-18T00:00:00.000Z
Link: CVE-2021-46384
No data.
Status : Modified
Published: 2022-03-04T22:15:19.307
Modified: 2024-11-21T06:34:00.853
Link: CVE-2021-46384
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA