Description
MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
Remediation
References
https://github.com/ming-soft/MCMS/issues/59
Related Vulnerabilities
CVE-2021-39194 Vulnerability in maven package com.charleskorn.kaml:kaml
CVE-2022-1245 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2023-36472 Vulnerability in npm package @strapi/plugin-content-manager
CVE-2023-45143 Vulnerability in npm package undici
CVE-2020-28472 Vulnerability in npm package @aws-sdk/shared-ini-file-loader