CVE-2023-51282: Code Injection
Published Jan 16, 2024
·Updated
An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.
Affected Software
2 affected components
maven/net.mingsoft:ms-mcms<=5.2.4
Mingsoft MCMS=5.2.4
Event History
Jan 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-51282?
CVE-2023-51282 is classified as a high severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2023-51282?
To mitigate CVE-2023-51282, upgrade MingSoft MCMS to version 5.2.5 or later.
3
What kind of attack does CVE-2023-51282 enable?
CVE-2023-51282 allows remote attackers to exploit a crafted script to access sensitive information via the password parameter.
4
Which versions of MingSoft MCMS are affected by CVE-2023-51282?
CVE-2023-51282 affects MingSoft MCMS version 5.2.4 and earlier.
5
Is CVE-2023-51282 related to any specific software?
Yes, CVE-2023-51282 specifically pertains to MingSoft MCMS version 5.2.4 and the Maven package net.mingsoft:ms-mcms.