CVE-2026-19355: MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection
A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19355?
The severity of CVE-2026-19355 is classified as high with a score of 7.3.
How do I fix CVE-2026-19355?
To fix CVE-2026-19355, update your MingSoft MCMS installation to version 3.0.7 or later, which addresses the SQL injection vulnerability.
What type of vulnerability is CVE-2026-19355?
CVE-2026-19355 is an SQL injection vulnerability that can be exploited through the ModelDataImpl.queryDiyFormData function.
Can CVE-2026-19355 be exploited remotely?
Yes, CVE-2026-19355 can be exploited remotely due to its nature as a SQL injection vulnerability.
What impact does CVE-2026-19355 have on data confidentiality?
CVE-2026-19355 may lead to a compromise of data confidentiality due to unauthorized SQL queries that can expose sensitive information.