CVE-2025-2194
- EPSS 0.09%
- Veröffentlicht 11.03.2025 13:31:04
- Zuletzt bearbeitet 09.04.2025 20:46:03
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file /admin/file/list.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument path leads t...
CVE-2025-2193
- EPSS 0.39%
- Veröffentlicht 11.03.2025 13:15:43
- Zuletzt bearbeitet 09.04.2025 20:48:27
A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/delete.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argumen...
CVE-2025-25768
- EPSS 0.06%
- Veröffentlicht 21.02.2025 19:15:14
- Zuletzt bearbeitet 04.04.2025 15:26:56
MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
CVE-2025-25767
- EPSS 0.08%
- Veröffentlicht 21.02.2025 19:15:14
- Zuletzt bearbeitet 22.04.2025 12:58:05
A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.
CVE-2025-25766
- EPSS 0.16%
- Veröffentlicht 21.02.2025 18:16:12
- Zuletzt bearbeitet 28.03.2025 18:46:37
An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.
- EPSS 0.03%
- Veröffentlicht 21.02.2025 18:16:12
- Zuletzt bearbeitet 28.03.2025 19:10:06
MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.
CVE-2024-48177
- EPSS 0.2%
- Veröffentlicht 28.10.2024 21:15:09
- Zuletzt bearbeitet 18.04.2025 01:23:30
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.
CVE-2024-25428
- EPSS 0.75%
- Veröffentlicht 20.02.2024 22:15:08
- Zuletzt bearbeitet 08.04.2025 13:19:04
SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.
CVE-2024-24160
- EPSS 0.16%
- Veröffentlicht 02.02.2024 16:15:55
- Zuletzt bearbeitet 09.05.2025 18:16:03
MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.
CVE-2024-24161
- EPSS 0.14%
- Veröffentlicht 02.02.2024 16:15:55
- Zuletzt bearbeitet 12.06.2025 15:15:37
MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.