An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23262
Reference (s):
- https://github.com/ming-soft/MCMS/issues/45

