zyh

2 exploits Active since Mar 2026
CVE-2026-29909 NOMISEC MEDIUM WORKING POC
MRCMS 3.1.2 - Unauthenticated Directory Enumeration via File Management Module
MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.
CVSS 5.3
CVE-2026-29909 WRITEUP MEDIUM WRITEUP
MRCMS 3.1.2 - Unauthenticated Directory Enumeration via File Management Module
MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.
CVSS 5.3