CVE-2022-36272: SQL Injection
Published Aug 16, 2022
·Updated
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.
Affected Software
1 affected component
Mingsoft MCMS=5.2.8
Event History
Aug 16, 2022
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-36272.
2
What is the severity of CVE-2022-36272?
The severity of CVE-2022-36272 is critical (9.8).
3
What is the affected software for CVE-2022-36272?
The affected software for CVE-2022-36272 is Mingsoft MCMS 5.2.8.
4
What is the CWE for CVE-2022-36272?
The CWE for CVE-2022-36272 is CWE-89.
5
Is there a fix available for CVE-2022-36272?
There is no known fix available for CVE-2022-36272 at the moment. It is recommended to follow the vendor's official security advisory for updates.