MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.
History

Mon, 30 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
Description MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-30T19:24:14.343Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-29909

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-30T17:16:15.750

Modified: 2026-03-30T17:16:15.750

Link: CVE-2026-29909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.