CVE-2024-46446
n/a n/a, mecha_cms, mecha 취약점
Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.
- 대응 우선순위
- 점검
- CVSS
- 9.8
- EPSS
- 1.36% 백분위 69.1% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2024.10.08