GHSA-54wc-49qj-5ghj
CRITICALCVE-2025-56316A SQL injection vulnerability in the contenttitle parameter of the /cms/content/list endpoint in MCMS 5.5.0 through 6.0.1 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.
- Affected
- >= 5.5.0, < 6.0.2
- Fixed in
- 6.0.2
- Weakness
- CWE-89
- Published
- 2025-10-17
- Source
- github