Report: CVE-2026-4953 - mingSoft MCMS Editor Endpoint BaseAction.java catchImage privilege escalation - Guide

Report: CVE-2026-4953 - mingSoft MCMS Editor Endpoint BaseAction.java catchImage privilege escalation - Guide

CVE ID :CVE-2026-4953 Published : March 27, 2026, 3:17 p.m. | 29 minutes ago Description :A weakness has been identified in mingSoft MCMS 迄 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 27, 2026
Affected Product: java