Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T parameter in a request and uses it as a hash of SQL statements without filtering, resulting in a SQL injection vulnerability in getChannel() in the ChannelService.java file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MRCMS 安全漏洞
Vulnerability Description
MRCMS(又名mushroom)是一套基于Java的动态内容管理系统。 MRCMS 3.1.2及之前版本中的ChannelService.java文件的‘getChannel()’函数存在安全漏洞,该漏洞源于WebParam.java文件没有进行过滤就直接接受了‘FIELD_T’参数并将它用作SQL语句的散列。攻击者可利用该漏洞查看、添加、修改或删除后端数据库中的信息。
CVSS Information
N/A
Vulnerability Type
N/A