SQL Injection Vulnerability in Mingsoft MCMS by Mingsoft
CVE-2022-30047
9.8CRITICAL
What is CVE-2022-30047?
Mingsoft MCMS version 5.2.7 is vulnerable to a SQL injection attack found in the '/mdiy/dict/listExcludeApp' URI through the 'orderBy' parameter. This flaw allows attackers to manipulate database queries via crafted requests, potentially leading to unauthorized data access or corruption.
