Description
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
Remediation
References
https://lycshub.github.io/2021/12/28/MCMS-vulnerabilities/
Related Vulnerabilities
CVE-2020-11023 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery
CVE-2020-28478 Vulnerability in npm package gsap
CVE-2021-37404 Vulnerability in maven package org.apache.hadoop:hadoop-common
CVE-2022-0508 Vulnerability in npm package @peertube/embed-api
CVE-2022-24999 Vulnerability in maven package org.webjars.npm:qs