CVE-2020-23262: SQL injection without credentials in ming-soft MCMS

Severity: Critical

CVSS Score: 9.8

An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.