An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://cms.com | product |
https://gitee.com/mingSoft/MCMS/issues/IBOOTX | issue tracking exploit |
https://gist.github.com/erdan111/38dcb5150b523436fe01249b2542f02f#file-cve-2025-29287 | third party advisory |