Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 30 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in mingSoft MCMS 迄 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. | A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. |
| Title | mingSoft MCMS Editor Endpoint BaseAction.java catchImage privilege escalation | mingSoft MCMS Editor Endpoint BaseAction.java catchImage server-side request forgery |
Fri, 27 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in mingSoft MCMS 迄 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. | |
| Title | mingSoft MCMS Editor Endpoint BaseAction.java catchImage privilege escalation | |
| First Time appeared |
Mingsoft
Mingsoft mcms |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:mingsoft:mcms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mingsoft
Mingsoft mcms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-30T12:05:18.706Z
Reserved: 2026-03-27T07:53:19.014Z
Link: CVE-2026-4953
Updated: 2026-03-30T12:05:14.898Z
Status : Deferred
Published: 2026-03-27T15:17:02.060
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-4953
No data.
OpenCVE Enrichment
Updated: 2026-03-30T07:01:51Z