Description
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
Remediation
References
https://github.com/ming-soft/MCMS/issues/59
Related Vulnerabilities
CVE-2013-2071 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-47321 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2020-28462 Vulnerability in npm package ion-parser
CVE-2017-16105 Vulnerability in npm package serverwzl
CVE-2021-37695 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4