-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| net.mingsoft:ms-mcms | maven | < 5.4.4 | 5.4.4 |
The vulnerability is an arbitrary file upload due to a misconfiguration in 'config.json' used by the UEditor component. The patch removes '.xml' from the allowed file types. The actual code that processes the upload and enforces this configuration resides in the UEditor's server-side scripts (like 'controller.jsp') and the Java libraries it uses (e.g., 'com.baidu.ueditor').
Ongoing coverage of React2Shell