-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| net.mingsoft:ms-mcms | maven | = 5.2.8 |
The vulnerability chain combines two functions: 1) BaseFileAction's upload validation only blocks specific extensions while allowing ZIP files, and 2) TemplateAction's ZIP parser extracts files without re-validating contained JSPs. This allows attackers to bypass front-end filtering by packaging JSP webshells in ZIP archives. The GitHub issue #95 explicitly demonstrates this exploit flow through these components.
KEV Misses 88% of Exploited CVEs- Get the report