SQL Injection Vulnerability in MCMS by Ming Soft
CVE-2022-27466
9.8CRITICAL
What is CVE-2022-27466?
The MCMS version 5.2.27 has been identified with a SQL injection vulnerability in the orderBy parameter at /dict/list.do. Successful exploitation of this vulnerability could allow an attacker to manipulate database queries, potentially leading to unauthorized data access or disclosure. This highlights the importance of input validation and secure coding practices to prevent such vulnerabilities in web applications.
