Cross-Site Request Forgery Vulnerability in MCMS by Ming Soft
CVE-2022-27340
8.8HIGH
What is CVE-2022-27340?
A Cross-Site Request Forgery vulnerability exists in MCMS version 5.2.7 through the endpoint /role/saveOrUpdateRole.do. This flaw permits attackers to exploit the application, leading to unauthorized privilege escalation and the potential modification of sensitive data without the user’s consent.
