Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Mushroom Content Management System Project Subscribe
Filtered by product Mushroom Content Management System
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17796 1 Mushroom Content Management System Project 1 Mushroom Content Management System 2018-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T parameter in a request and uses it as a hash of SQL statements without filtering, resulting in a SQL injection vulnerability in getChannel() in the ChannelService.java file.