Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.8
CVE-2018-18830
- EPSS 1.21%
- Veröffentlicht 30.10.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:42
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of J...
8.8
CVE-2018-17366
- EPSS 0.57%
- Veröffentlicht 23.09.2018 18:29:00
- Zuletzt bearbeitet 19.02.2026 18:39:55
An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.