PT-2026-29058 · Mrcms · Mrcms
Qflksheep
+1
·
Publicado
2026-03-30
·
Atualizado
2026-03-30
·
CVE-2026-29909
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MRCMS version 3.1.2
Description
The software contains an unauthenticated directory enumeration issue within the file management module. The
/admin/file/list.do API endpoint does not have authentication checks or proper input validation, which allows remote attackers to list directory contents on the server without needing to log in. The vulnerable parameter is not specified.Recommendations
Apply updates to address the issue in MRCMS version 3.1.2. As a temporary workaround, restrict access to the
/admin/file/list.do API endpoint.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mrcms