Lucene search

K
osvGoogleOSV:GHSA-H3HW-G4HM-7GR4
HistoryFeb 09, 2022 - 10:18 p.m.

SQL injection without credentials in ming-soft MCMS

2022-02-0922:18:13
Google
osv.dev
8
sql injection
ming-soft mcms
security issue
software

EPSS

0.002

Percentile

59.4%

An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.

EPSS

0.002

Percentile

59.4%