CVE-2026-19356: MingSoft MCMS ms-mdiy list information disclosure
A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19356?
CVE-2026-19356 has a medium severity rating of 5.3.
What does CVE-2026-19356 affect?
CVE-2026-19356 affects the MingSoft MCMS up to version 3.0.6, particularly the ms-mdiy component.
How does CVE-2026-19356 manifest?
CVE-2026-19356 allows for information disclosure through manipulation of the /mdiy/form/data/list file.
How can I fix CVE-2026-19356?
To mitigate CVE-2026-19356, ensure that you update MingSoft MCMS to the latest version that addresses this vulnerability.
Is CVE-2026-19356 exploitable remotely?
Yes, CVE-2026-19356 can be exploited remotely.