CVE-2022-30048: SQL Injection
Published May 11, 2022
·Updated
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
Affected Software
1 affected component
Mingsoft MCMS=5.2.7
Event History
May 11, 2022
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-30048?
The severity of CVE-2022-30048 is critical with a score of 9.8.
2
What is the affected software of CVE-2022-30048?
The affected software of CVE-2022-30048 is Mingsoft MCMS version 5.2.7.
3
What is the vulnerability type of CVE-2022-30048?
The vulnerability type of CVE-2022-30048 is SQL injection.
4
How can the SQL injection vulnerability in CVE-2022-30048 be exploited?
The SQL injection vulnerability in CVE-2022-30048 can be exploited through the orderBy parameter in the /mdiy/dict/list URI.
5
Is there a fix available for the SQL injection vulnerability in CVE-2022-30048?
At the moment, there is no information about the availability of a fix for the SQL injection vulnerability in CVE-2022-30048. It is recommended to follow the provided reference for updates.