QID 981228
QID 981228: Java (maven) Security Update for net.mingsoft:ms-mcms (GHSA-7hjp-97g3-rq93)
An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7hjp-97g3-rq93 for updates pertaining to this vulnerability.
Vendor References
- GHSA-7hjp-97g3-rq93 -
github.com/advisories/GHSA-7hjp-97g3-rq93
CVEs related to QID 981228
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7hjp-97g3-rq93 | net.mingsoft:ms-mcms |
|