CVE-2026-29909
EUVD-2026-1712930.03.2026, 17:16
MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mrcms | mrcms | 3.1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration