First published: Wed Jan 26 2022(Updated: )
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mingsoft MCMS | <=5.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-46383.
The severity of CVE-2021-46383 is high with a score of 7.5.
MCMS version <=5.2.5 is affected by CVE-2021-46383.
The impact of CVE-2021-46383 is the ability for an attacker to obtain sensitive information remotely.
The attack vector for CVE-2021-46383 is either 0 or sleep(3).
To fix CVE-2021-46383, you should update MCMS to a version higher than 5.2.5.
More information about CVE-2021-46383 can be found at https://gitee.com/mingSoft/MCMS/issues/I4QZ1I.