6.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
2 packages
- tmsu
- commitmsgfmt
- @LeSuisse dismissed
xiweicheng TMS FileController.java upload unrestricted upload
A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/controller/FileController.java. The manipulation of the argument filename results in unrestricted upload. The attack may be performed from remote. The exploit is now public and may be used.
References
- VDB-341629 | CTI Indicators (IOB, IOC, TTP, IOA) signature permissions-required
- Submit #731240 | https://gitee.com/xiweicheng/tms/ Merchant Mall - Mall Development/TMS 1.0 Unrestricted Upload third-party-advisory
- https://github.com/bkglfpp/CVE-md/blob/main/%E5%95%86%E6%88%B7%E5%95%86%E5%9F%8… exploit
- VDB-341629 | xiweicheng TMS FileController.java upload unrestricted upload vdb-entry technical-description
- Submit #731240 | https://gitee.com/xiweicheng/tms/ Merchant Mall - Mall Development/TMS 1.0 Unrestricted Upload third-party-advisory
- https://github.com/bkglfpp/CVE-md/blob/main/%E5%95%86%E6%88%B7%E5%95%86%E5%9F%8… exploit
- VDB-341629 | xiweicheng TMS FileController.java upload unrestricted upload vdb-entry technical-description
- VDB-341629 | CTI Indicators (IOB, IOC, TTP, IOA) signature permissions-required
Affected products
- ==2.11
- ==2.12
- ==2.9
- ==2.18
- ==2.22
- ==2.5
- ==2.25
- ==2.10
- ==2.6
- ==2.2
- ==2.16
- ==2.0
- ==2.27
- ==2.17
- ==2.23
- ==2.8
- ==2.19
- ==2.28.0
- ==2.1
- ==2.13
- ==2.24
- ==2.26
- ==2.20
- ==2.21
- ==2.14
- ==2.15
- ==2.4
- ==2.3
- ==2.7