AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-18830

CRITICAL · CVSS 9.8 EPSS 1.21%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-10-30 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-18830
Severity
CRITICAL
CVSS
9.8
EPSS
1.21%
Java

Original NVD Description

An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename, and then intercept the data packet. In the name parameter, change the suffix to jsp. In the response, the server returns the storage path of the file, which can be accessed to execute arbitrary JSP code.