A SQL injection vulnerability in the content_title...
Unreviewed
Published
Oct 17, 2025
to the GitHub Advisory Database
•
Updated Oct 17, 2025
Description
Published by the National Vulnerability Database
Oct 17, 2025
Published to the GitHub Advisory Database
Oct 17, 2025
Last updated
Oct 17, 2025
A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.
References