CVE-2021-46383: SQL Injection
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-46383.
What is the severity of CVE-2021-46383?
The severity of CVE-2021-46383 is high with a score of 7.5.
What is affected by CVE-2021-46383?
MCMS version <=5.2.5 is affected by CVE-2021-46383.
What is the impact of CVE-2021-46383?
The impact of CVE-2021-46383 is the ability for an attacker to obtain sensitive information remotely.
What is the attack vector for CVE-2021-46383?
The attack vector for CVE-2021-46383 is either 0 or sleep(3).
How can I fix CVE-2021-46383?
To fix CVE-2021-46383, you should update MCMS to a version higher than 5.2.5.
Where can I find more information about CVE-2021-46383?
More information about CVE-2021-46383 can be found at https://gitee.com/mingSoft/MCMS/issues/I4QZ1I.