SQL Injection Vulnerability in MingSoft MCMS Web Application
CVE-2026-19355

6.9MEDIUM

Key Information:

Vendor

Mingsoft

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-19355?

A vulnerability exists in MingSoft's MCMS, where improper handling of user input within the ModelDataImpl.queryDiyFormData function can lead to SQL injection attacks. This vulnerability is associated with the handling of the 'formFields' argument in the /mdiy/form/data/list.do file, making it possible for remote attackers to manipulate queries. Publicly disclosed exploits may already be in use, highlighting the urgency for users of affected versions to implement necessary security measures and updates.

Affected Version(s)

MCMS 3.0.0

MCMS 3.0.1

MCMS 3.0.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

murkfox (VulDB User)
VulDB CNA Team
.