Vulnerabilities > Mingsoft

DATE CVE VULNERABILITY TITLE RISK
2022-03-03 CVE-2022-25125 SQL Injection vulnerability in Mingsoft Mcms 5.2.4
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
network
low complexity
mingsoft CWE-89
7.5
2022-02-18 CVE-2021-46062 Unspecified vulnerability in Mingsoft Mcms 5.2.5
MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
network
mingsoft
5.8
2022-02-18 CVE-2021-46063 Code Injection vulnerability in Mingsoft Mcms 5.2.5
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
network
low complexity
mingsoft CWE-94
6.4
2022-02-18 CVE-2021-46036 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms 5.2.4
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
network
low complexity
mingsoft CWE-434
7.5
2022-02-18 CVE-2021-46037 Unspecified vulnerability in Mingsoft Mcms 5.2.4
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
network
low complexity
mingsoft
5.5
2022-02-17 CVE-2021-44868 SQL Injection vulnerability in Mingsoft Mcms 5.1
A problem was found in ming-soft MCMS v5.1.
network
low complexity
mingsoft CWE-89
7.5
2022-01-26 CVE-2021-46385 SQL Injection vulnerability in Mingsoft Mcms 4.6.5/5.2.4/5.2.5
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection.
network
low complexity
mingsoft CWE-89
5.0
2022-01-26 CVE-2021-46383 SQL Injection vulnerability in Mingsoft Mcms 4.6.5/5.2.4/5.2.5
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection.
network
low complexity
mingsoft CWE-89
5.0
2022-01-26 CVE-2021-46386 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
network
low complexity
mingsoft CWE-434
critical
9.8
2022-01-21 CVE-2022-22928 Use of Hard-coded Credentials vulnerability in Mingsoft Mcms 5.2.4
MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.
network
low complexity
mingsoft CWE-798
7.5