GHSA-hc5g-xf64-j49j

Suggest an improvement
Source
https://github.com/advisories/GHSA-hc5g-xf64-j49j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-hc5g-xf64-j49j/GHSA-hc5g-xf64-j49j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hc5g-xf64-j49j
Aliases
  • CVE-2022-4375
Published
2022-12-09T09:30:30Z
Modified
2023-11-08T04:10:46.217601Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Mingsoft MCMS vulnerable to SQL Injection
Details

A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.2.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215196.

Database specific
{
    "nvd_published_at": "2022-12-09T08:15:00Z",
    "github_reviewed_at": "2022-12-09T20:20:03Z",
    "severity": "CRITICAL",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-89"
    ]
}
References

Affected packages

Maven / net.mingsoft:ms-mcms

Package

Name
net.mingsoft:ms-mcms
View open source insights on deps.dev
Purl
pkg:maven/net.mingsoft/ms-mcms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.2.10

Affected versions

4.*

4.6.3-SNAPSHOTS
4.6.5
4.7.1
4.7.2

5.*

5.0.0
5.0.1
5.1
5.2
5.2.0
5.2.0.RELEASE
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9

Database specific

{
    "last_known_affected_version_range": "<= 5.2.9"
}