VYPR
High severityNVD Advisory· Published Feb 5, 2024· Updated Jun 17, 2025

CVE-2024-22567

CVE-2024-22567

Description

File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

MCMS 5.3.5 has an arbitrary file upload vulnerability in /ms/file/upload.do due to insufficient file extension filtering, allowing authenticated attackers to upload malicious files.

Vulnerability

Description MCMS 5.3.5 suffers from an arbitrary file upload vulnerability in the /ms/file/upload.do endpoint, as identified in the ManageFileAction.java controller [1]. The lack of strict filtering for file extensions allows attackers to bypass intended restrictions and upload files with dangerous extensions such as .jsp or .php [1].

Exploitation

To exploit this vulnerability, an attacker must first authenticate to the MCMS backend. Default credentials msopen/msopen are provided, which can be used to log in [1]. Once authenticated, the attacker can send a crafted POST request with a multipart form containing a malicious file to the upload endpoint. The code does not properly validate the file type, enabling the upload of arbitrary files to arbitrary directories [1].

Impact

Successful exploitation allows an attacker to upload a web shell or other malicious files, leading to remote code execution on the server. This could result in full compromise of the MCMS instance, data theft, or further lateral movement within the network [3].

Mitigation

As of the publication date, no official patch has been released. Users are advised to restrict file upload permissions, implement strict file extension whitelists, and change default credentials immediately. Additionally, disabling the upload endpoint if not required can reduce risk [1][3].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
net.mingsoft:ms-mcmsMaven
<= 5.3.5

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.