← Back to CVE List

CVE-2024-46446

Published: 2024-10-07T16:15Z
Last Modified: 2024-10-11T13:04Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt