Record summary

CVE-2022-23898 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryThrough 5.2.5affected

Nuclei templates

1
ProjectDiscoveryCRITICALMCMS 5.2.5 - SQL InjectionCVSS 9.8

MCMS 5.2.5 contains a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the SQL Injection vulnerability in MCMS 5.2.5.

WeaknessesCWE-89
AuthorsCo5mos
Template tagscvecve2022sqlimcmsmingsoftvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:mingsoft:mcms:5.2.5:*:*:*:*:*:*:*
Shodan: http.favicon.hash:1464851260
Shodan: http.favicon.hash:"1464851260"
FOFA: icon_hash="1464851260"

Source: ProjectDiscovery

References

3