PT-2026-20494 · Unknown · Mingsoft Mcms

Unnlucky1

·

Publicado

2026-02-18

·

Atualizado

2026-02-19

·

CVE-2026-2666

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mingSoft MCMS version 6.1.1
Description A flaw exists in mingSoft MCMS 6.1.1 related to unrestricted file upload. The issue is located within the Template Archive Handler component, specifically in a function associated with the /ms/file/uploadTemplate.do file. Manipulation of the File argument allows for unrestricted file uploads, and the attack can be initiated remotely. The exploit has been published.
Recommendations Apply any available updates or patches for mingSoft MCMS version 6.1.1. As a temporary workaround, restrict access to the /ms/file/uploadTemplate.do endpoint.

Exploit

Correção

Improper Access Control

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2666
GHSA-R9WP-QQ53-QVJX

Produtos afetados

Mingsoft Mcms