MCMS Arbitrary File Deletion vulnerability
High severity
GitHub Reviewed
Published
Feb 19, 2022
to the GitHub Advisory Database
•
Updated Sep 25, 2023
Description
Published by the National Vulnerability Database
Feb 18, 2022
Published to the GitHub Advisory Database
Feb 19, 2022
Reviewed
Mar 1, 2022
Last updated
Sep 25, 2023
net.mingsoft:ms-basic
is used for plugin management for applications built with Maven for the Mingfei Content Management System (MCMS). ms-basic before 2.1.16 is vulnerable to arbitrary file deletion using POST requests to/template/writeFileContent
via theoldFileName
parameter. MCMS before 5.2.11 is also vulnerable since it bundles vulnerable versions of ms-basic.References