A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.
{
"cwe_ids": [
"CWE-284"
],
"github_reviewed_at": "2026-02-19T20:30:51Z",
"nvd_published_at": "2026-02-18T20:18:37Z",
"severity": "LOW",
"github_reviewed": true
}