Sceawere
Vulnerability Detail
CVE-2026-19356UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MingSoft MCMS Information Disclosure Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 2h ago
- Vendor
- MingSoft
- Product
- MCMS
- Attack Type
- Information Disclosure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-09T14:17:26.930Z",
"pubdate": "2026-08-09T14:17:26.930Z",
"executiveSummary": "An information disclosure vulnerability has been identified in MingSoft MCMS up to version 3.0.6, specifically within the ms-mdiy component. The vulnerability resides in the handling of requests directed to the /mdiy/form/data/list endpoint. This security flaw allows remote attackers to bypass access controls and improperly access sensitive application data without authentication.\nThe impact of this vulnerability is significant, as successful exploitation results in the unauthorized exposure of internal system data, potentially leading to further reconnaissance or compromise of the underlying application infrastructure. The attack can be initiated entirely remotely over the network without requiring prior privileges or interaction from a legitimate user.\nPublicly available exploit code increases the risk of active exploitation in the wild. Despite early notification by security researchers, the vendor has failed to respond or provide an official patch. Consequently, organizations utilizing affected versions of MingSoft MCMS face an elevated risk of data exposure until alternative defensive measures are implemented.",
"technicalDetails": "The vulnerability is classified as an information disclosure flaw affecting the ms-mdiy component of MingSoft MCMS up to version 3.0.6. The root cause stems from inadequate input validation, authorization checks, or session verification within the backend logic handling requests to the /mdiy/form/data/list file path.\nFrom an architectural perspective, the vulnerable endpoint is designed to process data retrieval requests for dynamic forms within the MCMS framework. However, due to missing access control enforcement, an unauthenticated remote attacker can directly query this endpoint over HTTP or HTTPS to extract sensitive records managed by the system.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies a target instance of MingSoft MCMS running an affected version up to 3.0.6. Second, the attacker crafts a targeted HTTP request directed at the /mdiy/form/data/list URI, bypassing any intended front-end navigational restrictions. Third, the backend component processes the request and improperly queries the database or internal storage without validating whether the requesting entity possesses administrative or authorized privileges. Finally, the application serializes and returns the sensitive form data in the HTTP response, completing the information disclosure cycle.\nBecause the exploit vector is network-accessible and requires no prior authentication or specific privileges, external threat actors can easily automate data harvesting operations. Post-exploitation impact includes the exposure of confidential user inputs, administrative parameters, or internal business intelligence stored within the dynamic form data repositories, which can subsequently be leveraged to mount more advanced attacks against the hosting environment."
}