An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.
References
| Link | Resource |
|---|---|
| https://flowus.cn/share/7097c747-ae3e-4cef-a198-285863698607 | Exploit |
Configurations
History
No history.
Information
Published : 2025-02-21 18:16
Updated : 2025-03-28 18:46
NVD link : CVE-2025-25766
Mitre link : CVE-2025-25766
CVE.ORG link : CVE-2025-25766
JSON object : View
Products Affected
mrcms
- mrcms
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
