Sceawere

Vulnerability Detail

CVE-2026-19357UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MingSoft MCMS Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
MingSoft
Product
MCMS
Attack Type
Information Disclosure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-09T15:16:32.617Z",
  "pubdate": "2026-08-09T15:16:32.617Z",
  "executiveSummary": "An information disclosure vulnerability has been identified in MingSoft MCMS up to version 3.0.6, specifically within the ms-mdiy component. The security flaw resides in an unspecified function accessible via the file path /mdiy/form/get. This vulnerability allows remote, unauthenticated attackers to extract sensitive data without user interaction, presenting a significant risk to confidentiality. Public exploits are currently available, and the vendor has failed to respond to early vulnerability disclosure notifications, leaving deployed instances exposed to opportunistic scanning and data extraction attacks. Successful exploitation exposes sensitive system or application information, which can be leveraged for subsequent multi-stage attacks against the underlying infrastructure.",
  "technicalDetails": "The vulnerability stems from improper input validation and access control enforcement within the ms-mdiy component of MingSoft MCMS up to version 3.0.6. Specifically, the endpoint located at /mdiy/form/get fails to adequately verify the authorization state or privilege level of incoming requests before processing data retrieval operations. Consequently, a remote attacker can interact with this vulnerable function over the network without possessing valid credentials or session tokens.\nThe attack flow proceeds as follows: an unauthorized adversary crafts an HTTP request targeting the /mdiy/form/get URI. Due to the absence of strict access controls and missing authorization checks within the ms-mdiy component, the application processes the request and queries internal data structures. The endpoint subsequently returns sensitive information in the HTTP response payload to the client. This unauthorized retrieval mechanism bypasses application-layer security controls, directly exposing internal application data, configuration details, or user-submitted form records depending on the underlying data model associated with the requested function.\nNetwork exposure for this vulnerability is total, as the affected endpoint is reachable over standard HTTP/HTTPS protocols without requiring pre-existing privileges, specific roles, or complex authentication mechanisms. Publicly available exploit payloads leverage this direct exposure to automate the harvesting of sensitive data from vulnerable MingSoft MCMS instances. Post-exploitation impact is primarily characterized by a breach of confidentiality, where the harvested information can be utilized by threat actors to map internal application architectures, identify additional attack surfaces, or compromise user privacy."
}
CVE-2026-19357: MingSoft MCMS Information Disclosure (MEDIUM Severity, CVSS: 5.3) - Sceawere