CVE-2024-25428

Published
View on NVD ↗
CVSS v3
6.5
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.

MRCMS 是一款基于Java的智能内容管理系统,支持扩展、主题、AI (暂停维护,移步mrcms-v4)
GitHubGitHub
224