{"id":"GHSA-rpvr-mw7r-25xx","summary":"MCMS Arbitrary File Deletion vulnerability","details":"`net.mingsoft:ms-basic` is used for plugin management for applications built with Maven for the [Mingfei Content Management System (MCMS)](https://gitee.com/mingSoft/MCMS). ms-basic before 2.1.16 is vulnerable to arbitrary file deletion using POST requests to `/template/writeFileContent` via the `oldFileName` parameter. MCMS before 5.2.11 is also vulnerable since it bundles vulnerable versions of ms-basic.","aliases":["CVE-2021-46062"],"modified":"2024-02-16T08:11:34.370877Z","published":"2022-02-19T00:01:24Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-03-01T20:58:14Z","nvd_published_at":"2022-02-18T20:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-46062"},{"type":"WEB","url":"https://github.com/ming-soft/MCMS/issues/59"}],"affected":[{"package":{"name":"net.mingsoft:ms-basic","ecosystem":"Maven","purl":"pkg:maven/net.mingsoft/ms-basic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.16"}]}],"versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.20","1.0.21","1.0.22","1.0.23","1.0.24","1.0.25","1.0.26","1.0.27","1.0.28","1.0.29","1.0.30","1.0.31","1.0.32","1.0.33","1.0.34","1.0.35","1.0.36","1.0.37","1.0.38","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.13.1","2.1.13.2","2.1.13.3","2.1.13.4","2.1.14","2.1.14.1","2.1.15","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-rpvr-mw7r-25xx/GHSA-rpvr-mw7r-25xx.json"}},{"package":{"name":"net.mingsoft:ms-mcms","ecosystem":"Maven","purl":"pkg:maven/net.mingsoft/ms-mcms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.11"}]}],"versions":["4.6.3-SNAPSHOTS","4.6.5","4.7.1","4.7.2","5.0.0","5.0.1","5.1","5.2","5.2.0","5.2.0.RELEASE","5.2.1","5.2.10","5.2.2","5.2.3","5.2.4","5.2.5","5.2.6","5.2.7","5.2.8","5.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-rpvr-mw7r-25xx/GHSA-rpvr-mw7r-25xx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"}]}