Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

辛夷

#13741of 53,635
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2022-19983
9.8
2022-05-11
Mingsoft · Mingsoft Mcms · CVE-2022-30047
**Name of the Vulnerable Software and Affected Versions** Mingsoft MCMS version 5.2.7 **Description** A SQL injection issue was found in the /mdiy/dict/listExcludeApp URI via the `orderBy` parameter. This allows for potential exploitation. **Recommendations** For Mingsoft MCMS version 5.2.7, avoid using the `orderBy` parameter in the /mdiy/dict/listExcludeApp URI until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-19984
9.8
2022-05-11
Mingsoft · Mingsoft Mcms · CVE-2022-30048
**Name of the Vulnerable Software and Affected Versions** Mingsoft MCMS version 5.2.7 **Description** A SQL injection issue was found in the /mdiy/dict/list URI via the `orderBy` parameter. This allows for potential exploitation. No information is provided about the estimated number of affected devices or real-world incidents. **Recommendations** For Mingsoft MCMS version 5.2.7, consider restricting access to the /mdiy/dict/list URI or avoiding the use of the `orderBy` parameter until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.