Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-4953

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 7.3
CVSS2: 7.5
EPSS Низкий

Описание

A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

EPSS

Процентиль: 15%
0.0005
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.3
github
12 дней назад

A weakness has been identified in mingSoft MCMS 迄 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

EPSS

Процентиль: 15%
0.0005
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-918