CVE-2022-22930: Critical severity mcms vulnerability
Published Jan 20, 2022
·Updated
A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.
Affected Software
1 affected component
Mingsoft MCMS=5.2.4
Event History
Jan 20, 2022
CVE Published
via MITRE·11:40 PM
Data Sourced
via MITRE·11:40 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-22930.
2
What is the severity level of CVE-2022-22930?
CVE-2022-22930 has a severity level of critical.
3
What is the affected software version of CVE-2022-22930?
The affected software version of CVE-2022-22930 is MCMS v5.2.4.
4
How can attackers exploit CVE-2022-22930?
Attackers can exploit CVE-2022-22930 by executing arbitrary code via a crafted payload in the Template Management function of MCMS v5.2.4.
5
Is there a fix available for CVE-2022-22930?
Currently, there is no information available regarding a fix for CVE-2022-22930. It is recommended to follow the vendor's security advisory for updates.