GobyVuls/CVE-2022-22928.md
2023-04-13 15:26:50 +08:00

13 lines
1.1 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

## MCMS Shiro Deserialization Vulnerability (CVE-2022-22928)
| **Vulnerability** | **MCMS Shiro Deserialization Vulnerability (CVE-2022-22928)** |
| :----: | :-----|
| **Chinese name** | 铭飞 MCMS shiro 反序列化漏洞CVE-2022-22928 |
| **CVSS core** | 9.8 |
| **FOFA Query** (click to view the results directly)| [body=\"铭飞Mcms\" \|\| title=\"铭飞Mcms\"](https://en.fofa.info/result?qbase64=Ym9keT0i6ZOt6aOeTWNtcyIgfHwgdGl0bGU9IumTremjnk1jbXMi) |
| **Number of assets affected** | 295 |
| **Description** | Mingfei Mcms is a complete open source J2EE system of Mingfei Technology Co., Ltd. Mingfei Mcms V5 2.2 and earlier versions contain a security vulnerability, which stems from the existence of hard coded Shiro key in the software, which allows attackers to exploit the key and execute arbitrary code. |
| **Impact** | Attackers can use this vulnerability to arbitrarily execute code on the server side, write backdoors, obtain server permissions, and then control the entire web server. |
![](https://s3.bmp.ovh/imgs/2023/04/12/6e4ebece1945ba6f.gif)