CVE-2026-29909
MEDIUMMRCMS 3.1.2 - Unauthenticated Directory Enumeration via File Management Module
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2026-29909. PoCs published by SecureWithUmer, qflksheep.
AI-analyzed exploit summary The repository contains a minimal PoC for CVE-2026-29909, an unauthenticated directory enumeration vulnerability in MRCMS V3.1.2. The README describes the issue and provides a basic HTTP request to exploit the flaw but lacks functional exploit code or deeper technical analysis.
Description
MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.
Exploits (2)
The repository contains a minimal PoC for CVE-2026-29909, an unauthenticated directory enumeration vulnerability in MRCMS V3.1.2. The README describes the issue and provides a basic HTTP request to exploit the flaw but lacks functional exploit code or deeper technical analysis.
The repository provides a functional HTTP request PoC for CVE-2026-29909, demonstrating unauthenticated directory enumeration in MRCMS V3.1.2 via the /admin/file/list.do endpoint. The exploit leverages path traversal to access sensitive server directories without authentication.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N