First published: Thu Jan 20 2022(Updated: )
MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mingsoft MCMS | =5.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of MCMS is CVE-2022-22928.
The severity level of CVE-2022-22928 is Critical with a score of 9.8.
The affected software version of CVE-2022-22928 is MCMS v5.2.4.
Attackers can exploit CVE-2022-22928 by exploiting the hardcoded shiro-key to execute arbitrary code.
Yes, please refer to the reference link for more information on the fix for CVE-2022-22928.