PT-2026-29058 · Mrcms · Mrcms
Qflksheep
+1
·
Published
2026-03-30
·
Updated
2026-03-30
·
CVE-2026-29909
CVSS v3.1
5.3
Medium
| AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MRCMS version 3.1.2
Description
The software contains an unauthenticated directory enumeration issue within the file management module. The
/admin/file/list.do API endpoint does not have authentication checks or proper input validation, which allows remote attackers to list directory contents on the server without needing to log in. The vulnerable parameter is not specified.Recommendations
Apply updates to address the issue in MRCMS version 3.1.2. As a temporary workaround, restrict access to the
/admin/file/list.do API endpoint.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mrcms