CVE-2022-4350

LOW

Mingsoft MCMS 5.2.8 - Cross-Site Scripting via search.do content_title Parameter

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-215112.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory
https://gitee.com/mingSoft/MCMS/issues/I5MT8Y
Third Party Advisory
https://vuldb.com/?id.215112

Scores

CVSS v3 3.5
EPSS 0.0019
EPSS Percentile 40.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-707
Status published
Products (2)
mingsoft/mcms 5.2.8
net.mingsoft/ms-mcms 0Maven
Published Dec 08, 2022
Tracked Since Feb 18, 2026