Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-72gm-vcvr-mjgq

Опубликовано: 30 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.

EPSS

Процентиль: 6%
0.00021
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
nvd
19 дней назад

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.

EPSS

Процентиль: 6%
0.00021
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20