CVE-2025-56316 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL qu…
Critical CVSS: 9.8

CVE-2025-56316

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.
Vendor
Mingsoft
Product
Mcms
CWE
CWE-89
Yayın Tarihi
2025-10-17 19:15:37
Güncelleme
2025-10-28 16:44:48
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar