Back to Labs
Security Advisory

CVE-2021-46386

About

File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.

Weakness (CWE):CWE-434

Rainforest analyst review

mingSoft MCMS lets a remote attacker upload a crafted jspx web shell to the FileAction#upload handler and thereby execute arbitrary code on the server. This is an unauthenticated file-upload-to-RCE in a content management system: the upload path doesn't stop an executable JSPX file from landing where the server will run it, so a single crafted request converts into a web shell and full control of the CMS host.

Unauthenticated RCE in an installable CMS is prime botnet fodder. There's no credential to obtain and no user to phish, so once the vulnerable path is public, automated scanners tend to hit every reachable MCMS install looking for the FileAction upload endpoint. The result of a successful drop is the standard web-shell playbook — defacement, SEO spam, cryptomining, data theft, or a pivot into the hosting network — and the version boundary, through 5.2.5, is all that separates an exposed site from compromise.

As with any self-hosted CMS, our real problem is discovery, not comprehension. MCMS installs tend to be stood up per-project and rarely tracked centrally, so the work is enumerating which instances we (or teams we support) actually run, at what version, and which expose the upload path to the internet. That reachable-and-vulnerable intersection is the urgent set; where patching to a fixed release lags, blocking or authenticating the FileAction upload endpoint at the proxy is the stopgap, and any exposed pre-5.2.5 install is treated as suspect until proven clean.

References

Related CVEs

Frequently asked questions

What is CVE-2021-46386?

File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.

How severe is CVE-2021-46386?

CVE-2021-46386 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2021-46386 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2021-46386?

Public advisories list the following as affected: mcms. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2021-46386?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email