CVE-2023-50578: SQL Injection
Published Dec 30, 2023
·Updated
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
Affected Software
2 affected components
maven/net.mingsoft:ms-mcms<=5.2.9
Mingsoft MCMS=5.2.9
Event History
Dec 30, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-50578?
CVE-2023-50578 has a high severity due to its potential for unauthorized database access through SQL injection.
2
How do I fix CVE-2023-50578?
To fix CVE-2023-50578, update Mingsoft MCMS to a version beyond 5.2.9 or implement input validation to prevent SQL injection.
3
What software is affected by CVE-2023-50578?
CVE-2023-50578 affects Mingsoft MCMS version 5.2.9.
4
What type of vulnerability is CVE-2023-50578?
CVE-2023-50578 is classified as a SQL injection vulnerability.
5
Can CVE-2023-50578 expose sensitive data?
Yes, CVE-2023-50578 can potentially expose sensitive data if exploited by an attacker.