Aller au contenu

Fiche vulnérabilité

CVE-2021-46384 : faille critique mingsoft mcms (CVSS 9.8)

Description

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to compromise MCMS. Successful attacks of this vulnerability can result in takeover of MCMS.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
4 mars 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • mingsoft mcms

Références

Rechercher une autre vulnérabilité dans la base CVE