An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5
Published Oct 30, 2018
9.8
CRITICALCVSS 3.0
EPSS 1.21%
Description
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename, and then intercept the data packet. In the name parameter, change the suffix to jsp. In the response, the server returns the storage path of the file, which can be accessed to execute arbitrary JSP code.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.21% (0.01205) | 67.17th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.21% (0.01205) | 66.90th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.19% (0.00195) | 57.41th | v3 (v2023.03.01) |
| Jan 24, 2024 | 0.19% (0.00195) | 57.43th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.19% (0.00195) | 55.43th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.44% (0.00442) | 10.76th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.44% (0.00442) | 0.00th | v1 |
References (3)
- https://gitee.com/mingSoft/MCMS/issues/IO0IQ x_refsource_MISCThird Party Advisory
- https://github.com/advisories/GHSA-c7c7-xm8g-xm36 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-18830
| Link | Providers | Tags |
|---|---|---|
| https://gitee.com/mingSoft/MCMS/issues/IO0IQ | x_refsource_MISCThird Party Advisory | |
| https://github.com/advisories/GHSA-c7c7-xm8g-xm36 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-18830 |
Change history (0)
No recorded changes yet.