CVE-2025-29287 Details
Description
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
A vulnerability allowing arbitrary file upload has been identified in the ueditor component of MCMS version 5.4.3. This issue enables attackers to upload crafted files that could execute arbitrary code, potentially leading to malicious effects on the user.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitee.com/mingSoft/MCMS/issues/IBOOTX | CISA-ADP | ExploitIssue Tracking |
| https://gist.github.com/erdan111/38dcb5150b523436fe01249b2542f02f#file-cve-2025-29287 | [email protected] | Third Party Advisory |
| https://gitee.com/mingSoft/MCMS/issues/IBOOTX | [email protected] | ExploitIssue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mingsoft mcms | 5.4.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2025 | Initial Analysis | [email protected] |
| Apr 21, 2025 | New CVE Received | [email protected] |
| Apr 21, 2025 | CVE Modified | CISA-ADP |