CVE-2022-22928: Critical severity mcms vulnerability
Published Jan 20, 2022
·Updated
MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.
Affected Software
1 affected component
Mingsoft MCMS=5.2.4
Event History
Jan 20, 2022
CVE Published
via MITRE·11:40 PM
Data Sourced
via MITRE·11:40 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of MCMS?
The vulnerability ID of MCMS is CVE-2022-22928.
2
What is the severity level of CVE-2022-22928?
The severity level of CVE-2022-22928 is Critical with a score of 9.8.
3
What is the affected software version of CVE-2022-22928?
The affected software version of CVE-2022-22928 is MCMS v5.2.4.
4
How can attackers exploit CVE-2022-22928?
Attackers can exploit CVE-2022-22928 by exploiting the hardcoded shiro-key to execute arbitrary code.
5
Is there a fix available for CVE-2022-22928?
Yes, please refer to the reference link for more information on the fix for CVE-2022-22928.