CVE-2025-2196
- EPSS 0.09%
- Veröffentlicht 11.03.2025 14:00:10
- Zuletzt bearbeitet 10.04.2025 10:53:23
A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /admin/file/upload.do of the component org.marker.mushroom.controller.FileController. The manipulation of...
CVE-2025-2195
- EPSS 0.09%
- Veröffentlicht 11.03.2025 13:31:06
- Zuletzt bearbeitet 09.04.2025 20:45:17
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument name/p...
CVE-2025-2194
- EPSS 0.09%
- Veröffentlicht 11.03.2025 13:31:04
- Zuletzt bearbeitet 09.04.2025 20:46:03
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file /admin/file/list.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument path leads t...
CVE-2025-2193
- EPSS 0.39%
- Veröffentlicht 11.03.2025 13:15:43
- Zuletzt bearbeitet 09.04.2025 20:48:27
A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/delete.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argumen...
CVE-2025-25768
- EPSS 0.05%
- Veröffentlicht 21.02.2025 19:15:14
- Zuletzt bearbeitet 04.04.2025 15:26:56
MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
CVE-2025-25767
- EPSS 0.09%
- Veröffentlicht 21.02.2025 19:15:14
- Zuletzt bearbeitet 22.04.2025 12:58:05
A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.
CVE-2025-25766
- EPSS 0.13%
- Veröffentlicht 21.02.2025 18:16:12
- Zuletzt bearbeitet 28.03.2025 18:46:37
An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.
- EPSS 0.04%
- Veröffentlicht 21.02.2025 18:16:12
- Zuletzt bearbeitet 28.03.2025 19:10:06
MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.
CVE-2024-48177
- EPSS 0.28%
- Veröffentlicht 28.10.2024 21:15:09
- Zuletzt bearbeitet 18.04.2025 01:23:30
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.
CVE-2024-25428
- EPSS 0.88%
- Veröffentlicht 20.02.2024 22:15:08
- Zuletzt bearbeitet 08.04.2025 13:19:04
SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.