GobyVuls/CVE-2022-22928.md
2023-04-13 15:26:50 +08:00

1.1 KiB
Raw Permalink Blame History

MCMS Shiro Deserialization Vulnerability (CVE-2022-22928)

Vulnerability MCMS Shiro Deserialization Vulnerability (CVE-2022-22928)
Chinese name 铭飞 MCMS shiro 反序列化漏洞CVE-2022-22928
CVSS core 9.8
FOFA Query (click to view the results directly) body="铭飞Mcms" || title="铭飞Mcms"
Number of assets affected 295
Description Mingfei Mcms is a complete open source J2EE system of Mingfei Technology Co., Ltd. Mingfei Mcms V5 2.2 and earlier versions contain a security vulnerability, which stems from the existence of hard coded Shiro key in the software, which allows attackers to exploit the key and execute arbitrary code.
Impact Attackers can use this vulnerability to arbitrarily execute code on the server side, write backdoors, obtain server permissions, and then control the entire web server.