First published: Thu Jan 20 2022(Updated: )
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mingsoft MCMS | =5.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23314 is a SQL injection vulnerability in MCMS v5.2.4.
The SQL injection vulnerability in MCMS v5.2.4 can be exploited via the /ms/mdiy/model/importJson.do endpoint.
The severity of CVE-2022-23314 is rated as critical with a CVSS score of 9.8.
MCMS v5.2.4 is the affected software version for CVE-2022-23314.
At the moment, there is no specific patch or fix available for CVE-2022-23314. It is recommended to update to a version of MCMS that is not affected by this vulnerability if possible.