Sceawere
Vulnerability Detail
CVE-2026-19357UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MingSoft MCMS Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 4h ago
- Vendor
- MingSoft
- Product
- MCMS
- Attack Type
- Information Disclosure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-09T15:16:32.617Z",
"pubdate": "2026-08-09T15:16:32.617Z",
"executiveSummary": "An information disclosure vulnerability has been identified in MingSoft MCMS up to version 3.0.6, specifically within the ms-mdiy component. The security flaw resides in an unspecified function accessible via the file path /mdiy/form/get. This vulnerability allows remote, unauthenticated attackers to extract sensitive data without user interaction, presenting a significant risk to confidentiality. Public exploits are currently available, and the vendor has failed to respond to early vulnerability disclosure notifications, leaving deployed instances exposed to opportunistic scanning and data extraction attacks. Successful exploitation exposes sensitive system or application information, which can be leveraged for subsequent multi-stage attacks against the underlying infrastructure.",
"technicalDetails": "The vulnerability stems from improper input validation and access control enforcement within the ms-mdiy component of MingSoft MCMS up to version 3.0.6. Specifically, the endpoint located at /mdiy/form/get fails to adequately verify the authorization state or privilege level of incoming requests before processing data retrieval operations. Consequently, a remote attacker can interact with this vulnerable function over the network without possessing valid credentials or session tokens.\nThe attack flow proceeds as follows: an unauthorized adversary crafts an HTTP request targeting the /mdiy/form/get URI. Due to the absence of strict access controls and missing authorization checks within the ms-mdiy component, the application processes the request and queries internal data structures. The endpoint subsequently returns sensitive information in the HTTP response payload to the client. This unauthorized retrieval mechanism bypasses application-layer security controls, directly exposing internal application data, configuration details, or user-submitted form records depending on the underlying data model associated with the requested function.\nNetwork exposure for this vulnerability is total, as the affected endpoint is reachable over standard HTTP/HTTPS protocols without requiring pre-existing privileges, specific roles, or complex authentication mechanisms. Publicly available exploit payloads leverage this direct exposure to automate the harvesting of sensitive data from vulnerable MingSoft MCMS instances. Post-exploitation impact is primarily characterized by a breach of confidentiality, where the harvested information can be utilized by threat actors to map internal application architectures, identify additional attack surfaces, or compromise user privacy."
}