Description
SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.
Remediation
References
https://github.com/ming-soft/MCMS/issues/27
Related Vulnerabilities
CVE-2022-38900 Vulnerability in maven package org.webjars.npm:decode-uri-component
CVE-2011-0013 Vulnerability in maven package tomcat:catalina
CVE-2019-17495 Vulnerability in maven package org.webjars.bower:swagger-ui
CVE-2018-18950 Vulnerability in maven package org.webjars.bowergithub.kindsoft:kindeditor