CVE-2020-23262: SQL Injection
Published Jan 22, 2021
·Updated
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
Affected Software
1 affected component
Mingsoft MCMS=5.0.0
Event History
Jan 22, 2021
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23262?
CVE-2020-23262 has a high severity rating due to its exploit allowing SQL injection attacks.
2
How do I fix CVE-2020-23262?
To fix CVE-2020-23262, upgrade the Mingsoft MCMS software to a version where the SQL injection vulnerability is patched.
3
What systems are affected by CVE-2020-23262?
CVE-2020-23262 specifically affects Mingsoft MCMS version 5.0.0.
4
Can CVE-2020-23262 be exploited without authentication?
Yes, CVE-2020-23262 can be exploited by a malicious user without needing to log in.
5
What type of vulnerability is CVE-2020-23262?
CVE-2020-23262 is classified as a SQL injection vulnerability.