Description
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
Remediation
References
https://lycshub.github.io/2021/12/28/MCMS-vulnerabilities/
Related Vulnerabilities
CVE-2020-26938 Vulnerability in npm package oauth2-server
CVE-2022-21169 Vulnerability in npm package express-xss-sanitizer
CVE-2020-11009 Vulnerability in maven package org.rundeck:rundeck
CVE-2021-25979 Vulnerability in npm package apostrophe
CVE-2020-13957 Vulnerability in maven package org.apache.solr:solr-solrj