Information Disclosure Vulnerability in MingSoft MCMS by MingSoft
CVE-2026-19357
6.9MEDIUM
What is CVE-2026-19357?
A security vulnerability identified in MingSoft MCMS versions up to 3.0.6 affects an unknown functionality within the /mdiy/form/get file of the ms-mdiy component. This vulnerability allows for information disclosure, which can be exploited remotely. There has been public release of the exploit method, posing a significant risk to affected users. Despite attempts to notify the vendor about this critical issue, there has been no response. Organizations utilizing this product should take immediate steps to assess their exposure and implement necessary protections.
Affected Version(s)
MCMS 3.0.0
MCMS 3.0.1
MCMS 3.0.2
