CVE-2022-23898: SQL Injection
Published Mar 3, 2022
·Updated
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
Affected Software
1 affected component
Mingsoft MCMS=5.2.5
Event History
Mar 3, 2022
CVE Published
via MITRE·06:01 PM
Data Sourced
via MITRE·06:01 PM
Description
Frequently Asked Questions
1
What is CVE-2022-23898?
CVE-2022-23898 is a SQL injection vulnerability discovered in MCMS v5.2.5.
2
How severe is CVE-2022-23898?
CVE-2022-23898 has a severity rating of 9.8 (Critical).
3
What is the affected software for CVE-2022-23898?
MCMS v5.2.5 is the affected software for CVE-2022-23898.
4
How can I fix the SQL injection vulnerability in MCMS v5.2.5?
To fix the SQL injection vulnerability in MCMS v5.2.5, apply the latest security patches or updates provided by Mingsoft.
5
Where can I find more information about CVE-2022-23898?
More information about CVE-2022-23898 can be found at the following link: [CVE-2022-23898](https://github.com/ming-soft/MCMS/issues/62)