CVE-2022-23314: SQL Injection
Published Jan 20, 2022
·Updated
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
Affected Software
1 affected component
Mingsoft MCMS=5.2.4
Event History
Jan 20, 2022
CVE Published
via MITRE·11:40 PM
Data Sourced
via MITRE·11:40 PM
Description
Frequently Asked Questions
1
What is CVE-2022-23314?
CVE-2022-23314 is a SQL injection vulnerability in MCMS v5.2.4.
2
How can the SQL injection vulnerability in MCMS v5.2.4 be exploited?
The SQL injection vulnerability in MCMS v5.2.4 can be exploited via the /ms/mdiy/model/importJson.do endpoint.
3
What is the severity level of CVE-2022-23314?
The severity of CVE-2022-23314 is rated as critical with a CVSS score of 9.8.
4
What software version is affected by CVE-2022-23314?
MCMS v5.2.4 is the affected software version for CVE-2022-23314.
5
Is there any patch or fix available for CVE-2022-23314?
At the moment, there is no specific patch or fix available for CVE-2022-23314. It is recommended to update to a version of MCMS that is not affected by this vulnerability if possible.