Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12370 | An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. |
Github GHSA |
GHSA-3922-2r6r-r4fv | MCMS allows arbitrary file uploads in the ueditor component |
Thu, 24 Apr 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mingsoft
Mingsoft mcms |
|
| CPEs | cpe:2.3:a:mingsoft:mcms:5.4.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Mingsoft
Mingsoft mcms |
Mon, 21 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 | |
| Metrics |
cvssV3_1
|
Mon, 21 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-21T14:58:53.312Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29287
Updated: 2025-04-21T14:58:44.908Z
Status : Analyzed
Published: 2025-04-21T15:15:59.930
Modified: 2025-04-24T16:37:54.607
Link: CVE-2025-29287
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA