Description
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
Remediation
References
https://lycshub.github.io/2021/12/28/MCMS-vulnerabilities/
Related Vulnerabilities
CVE-2021-28860 Vulnerability in npm package mixme
CVE-2023-44487 Vulnerability in maven package io.helidon.http:helidon-http-http2
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:ua-parser-js
CVE-2020-14061 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2017-16138 Vulnerability in maven package org.webjars:mime