Description
A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2026-02-18: | Advisory disclosed |
| 2026-02-18: | VulDB entry created |
| 2026-02-21: | VulDB entry last update |
Credits
Unnlucky1 (VulDB User)
References
vuldb.com/?id.346463 (VDB-346463 | mingSoft MCMS Template Archive uploadTemplate.do unrestricted upload)
vuldb.com/?ctiid.346463 (VDB-346463 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.753243 (Submit #753243 | mingSoft MCMS 6.1.1 Conditional competition)
github.com/chujianxin0101/vuln/issues/11
github.com/chujianxin0101/vuln/issues/11