First published: Fri Jan 22 2021(Updated: )
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mingsoft MCMS | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23262 has a high severity rating due to its exploit allowing SQL injection attacks.
To fix CVE-2020-23262, upgrade the Mingsoft MCMS software to a version where the SQL injection vulnerability is patched.
CVE-2020-23262 specifically affects Mingsoft MCMS version 5.0.0.
Yes, CVE-2020-23262 can be exploited by a malicious user without needing to log in.
CVE-2020-23262 is classified as a SQL injection vulnerability.