SQL Injection Vulnerability in MCMS by MingSoft
CVE-2022-23899
9.8CRITICAL
What is CVE-2022-23899?
MCMS version 5.2.5 is affected by a SQL injection vulnerability that can be exploited via the search.do functionality located in the /web/MCmsAction.java file. This flaw may allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized data access or manipulation.
