Critical severity9.8NVD Advisory· Published Jan 26, 2022· Updated Jun 17, 2026
CVE-2021-46386
CVE-2021-46386
Description
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net.mingsoft:ms-mcmsMaven | <= 5.2.5 | — |
Affected products
2Patches
Vulnerability mechanics
References
3- gitee.com/mingSoft/MCMS/issues/I4R0GWnvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-cwx9-rp4w-4545ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-46386ghsaADVISORY
News mentions
0No linked articles in our index yet.