Sceawere

Vulnerability Detail

CVE-2026-19356UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MingSoft MCMS Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
MingSoft
Product
MCMS
Attack Type
Information Disclosure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-09T14:17:26.930Z",
  "pubdate": "2026-08-09T14:17:26.930Z",
  "executiveSummary": "An information disclosure vulnerability has been identified in MingSoft MCMS up to version 3.0.6, specifically within the ms-mdiy component. The vulnerability resides in the handling of requests directed to the /mdiy/form/data/list endpoint. This security flaw allows remote attackers to bypass access controls and improperly access sensitive application data without authentication.\nThe impact of this vulnerability is significant, as successful exploitation results in the unauthorized exposure of internal system data, potentially leading to further reconnaissance or compromise of the underlying application infrastructure. The attack can be initiated entirely remotely over the network without requiring prior privileges or interaction from a legitimate user.\nPublicly available exploit code increases the risk of active exploitation in the wild. Despite early notification by security researchers, the vendor has failed to respond or provide an official patch. Consequently, organizations utilizing affected versions of MingSoft MCMS face an elevated risk of data exposure until alternative defensive measures are implemented.",
  "technicalDetails": "The vulnerability is classified as an information disclosure flaw affecting the ms-mdiy component of MingSoft MCMS up to version 3.0.6. The root cause stems from inadequate input validation, authorization checks, or session verification within the backend logic handling requests to the /mdiy/form/data/list file path.\nFrom an architectural perspective, the vulnerable endpoint is designed to process data retrieval requests for dynamic forms within the MCMS framework. However, due to missing access control enforcement, an unauthenticated remote attacker can directly query this endpoint over HTTP or HTTPS to extract sensitive records managed by the system.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies a target instance of MingSoft MCMS running an affected version up to 3.0.6. Second, the attacker crafts a targeted HTTP request directed at the /mdiy/form/data/list URI, bypassing any intended front-end navigational restrictions. Third, the backend component processes the request and improperly queries the database or internal storage without validating whether the requesting entity possesses administrative or authorized privileges. Finally, the application serializes and returns the sensitive form data in the HTTP response, completing the information disclosure cycle.\nBecause the exploit vector is network-accessible and requires no prior authentication or specific privileges, external threat actors can easily automate data harvesting operations. Post-exploitation impact includes the exposure of confidential user inputs, administrative parameters, or internal business intelligence stored within the dynamic form data repositories, which can subsequently be leveraged to mount more advanced attacks against the hosting environment."
}
CVE-2026-19356: MingSoft MCMS Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere