CVE-2021-46384
Last modified
CVE-2021-46384 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). EPSS estimates a 2.08% chance of exploitation in the next 30 days.
Description
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to compromise MCMS. Successful attacks of this vulnerability can result in takeover of MCMS.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mingsoft | Mcms | <= 5.2.5 |
References
- https://gitee.com/mingSoft/MCMS/issues/I4QZ1OExploit, Issue Tracking, Third Party Advisory
- https://gitee.com/mingSoft/MCMS/issues/I4QZ1OExploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-46384?
How severe is CVE-2021-46384?
How do I fix CVE-2021-46384?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-46378DLink DIR850 ET850-1.08TRb03 is affected by an incorrect acc…7.5
- CVE-2021-46379DLink DIR850 ET850-1.08TRb03 is affected by an incorrect acc…6.1
- CVE-2021-46380Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-46381Local File Inclusion due to path traversal in D-Link DAP-162…7.5
- CVE-2021-46382Unauthenticated cross-site scripting (XSS) in Netgear WAC120…6.1
- CVE-2021-46383https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by:…7.5
- CVE-2021-46385https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by:…7.5
- CVE-2021-46386File upload vulnerability in mingSoft MCMS through 5.2.5, al…9.8
- CVE-2021-46387ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected …6.1
- CVE-2021-46388Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-46389IIPImage High Resolution Streaming Image Server prior to com…7.5
- CVE-2021-46390An access control issue in the authentication module of Lexa…6.8
Are you affected by CVE-2021-46384?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
