Executive brief
MCMS allows arbitrary file uploads in the ueditor component
Affected products
- Maven net.mingsoft:ms-mcms
Junglewise Threat Intelligence
CVE-2025-29287 · Severity: low · CVSS 3.1 · Published 2025-04-21
Technologies: net.mingsoft:ms-mcms (Maven). Vendors: Maven.
MCMS allows arbitrary file uploads in the ueditor component