CVE-2026-88414: SQL Injection
Published Sep 22, 2026
·Updated
MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do).
Affected Software
1 affected component
MCMS>=6.1.1<=6.2.1
Event History
Sep 22, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
Description
Frequently Asked Questions
1
Which MCMS versions are affected?
MCMS versions 6.1.1 through 6.2.1 are identified as affected.
2
Which endpoint should defenders review for exposure?
Review the PageAction.verify endpoint at GET /ms/mdiy/page/verify.do, which is identified as containing the SQL injection vulnerability.