CVE-2022-30047: SQL Injection
Published May 11, 2022
·Updated
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
Affected Software
1 affected component
Mingsoft MCMS=5.2.7
Event History
May 11, 2022
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
Description
Frequently Asked Questions
1
What is CVE-2022-30047?
CVE-2022-30047 is a SQL injection vulnerability discovered in Mingsoft MCMS v5.2.7.
2
How severe is CVE-2022-30047?
CVE-2022-30047 has a severity rating of 9.8, which is classified as critical.
3
How does CVE-2022-30047 affect Mingsoft MCMS v5.2.7?
CVE-2022-30047 affects Mingsoft MCMS v5.2.7 by allowing SQL injection through the orderBy parameter in the /mdiy/dict/listExcludeApp URI.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-30047?
CVE-2022-30047 is associated with CWE-89, which is the CWE ID for SQL injection vulnerabilities.
5
Where can I find more information about CVE-2022-30047?
More information about CVE-2022-30047 can be found at this reference link: [https://gitee.com/mingSoft/MCMS/issues/I54VLM](https://gitee.com/mingSoft/MCMS/issues/I54VLM)