CVE-2022-25125: SQL Injection
Published Mar 3, 2022
·Updated
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
Affected Software
1 affected component
Mingsoft MCMS=5.2.4
Event History
Mar 3, 2022
CVE Published
via MITRE·06:01 PM
Data Sourced
via MITRE·06:01 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25125?
CVE-2022-25125 is a SQL injection vulnerability discovered in MCMS v5.2.4.
2
How severe is CVE-2022-25125?
CVE-2022-25125 has a severity rating of 9.8, which is classified as critical.
3
How does CVE-2022-25125 affect MCMS v5.2.4?
CVE-2022-25125 affects MCMS v5.2.4 by allowing SQL injection via search.do in the file /mdiy/dict/listExcludeApp.
4
What is the affected software for CVE-2022-25125?
MCMS v5.2.4 is the affected software for CVE-2022-25125.
5
Is there a solution for CVE-2022-25125?
Yes, a solution for CVE-2022-25125 is available. Please refer to the provided reference for more information.