SQL Injection Vulnerability in Ming-Soft MCMS Version 4.7.2
CVE-2020-20913
9.8CRITICAL
What is CVE-2020-20913?
An SQL Injection vulnerability exists in Ming-Soft MCMS version 4.7.2, enabling remote attackers to execute arbitrary SQL code via the 'basic_title' parameter. This flaw can lead to unauthorized access to the database, data manipulation, or even full control over the application, putting user information and service integrity at risk.
