SQL Injection Vulnerability in MCMS by Ming Soft
CVE-2025-56316
9.8CRITICAL
What is CVE-2025-56316?
A vulnerability in MCMS 5.5.0 enables remote attackers to execute arbitrary SQL queries through the content_title parameter in the /cms/content/list endpoint. This issue arises from unsanitized input being processed in FreeMarker template rendering, which can lead to unauthorized data manipulation and potential exposure of sensitive information.
