Description
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
Remediation
References
https://github.com/ming-soft/MCMS/issues/45
Related Vulnerabilities
CVE-2023-4863 Vulnerability in npm package electron
CVE-2023-42276 Vulnerability in maven package cn.hutool:hutool-json
CVE-2022-40309 Vulnerability in maven package org.apache.archiva:maven2-repository
CVE-2023-31718 Vulnerability in npm package @frangoteam/fuxa
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.freemarker