SQL Injection Vulnerability in Mingsoft MCMS Web Content Management System
CVE-2022-30048
9.8CRITICAL
What is CVE-2022-30048?
Mingsoft MCMS version 5.2.7 has a SQL injection vulnerability that affects the /mdiy/dict/list URI via the orderBy parameter. This flaw allows attackers to execute arbitrary SQL queries, potentially leading to unauthorized data access and manipulation. It's essential for users of this CMS to implement security measures to mitigate the risks associated with this vulnerability.
