Description
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.
Remediation
References
https://github.com/ming-soft/MCMS
https://github.com/ming-soft/MCMS/issues/42
Related Vulnerabilities
CVE-2023-27564 Vulnerability in npm package n8n
CVE-2023-3691 Vulnerability in maven package org.webjars.bowergithub.diguoyihao:layui
CVE-2019-19771 Vulnerability in npm package bitcion-ops
CVE-2023-46133 Vulnerability in npm package crypto-es
CVE-2018-16489 Vulnerability in maven package org.webjars.npm:just-extend