Description
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
Remediation
References
https://lycshub.github.io/2021/12/28/MCMS-vulnerabilities/
Related Vulnerabilities
CVE-2022-1291 Vulnerability in maven package org.webjars.bower:tableexport.jquery.plugin
CVE-2021-46440 Vulnerability in npm package strapi
CVE-2022-22984 Vulnerability in npm package @snyk/snyk-cocoapods-plugin
CVE-2020-28281 Vulnerability in npm package set-object-value
CVE-2021-21346 Vulnerability in maven package com.thoughtworks.xstream:xstream