在 MingSoft MCMS 3.0.6 及更早版本中发现了一个漏洞。该漏洞影响组件 ms-mdiy 中的 /mdiy/form/data/list.do 文件里的 ModelDataImpl.queryDiyFormData 函数。对参数 formFields 的操纵可能导致 SQL 注入。该攻击可以由远程执行。此漏洞已被公开披露,且可能被利用。我们很早联系了供应商关于此漏洞的披露事宜,但供应商没有任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19356 | 5.3 MEDIUM | MingSoft MCMS ms-mdiy list information disclosure |
| CVE-2026-19357 | 5.3 MEDIUM | MingSoft MCMS ms-mdiy get information disclosure |
No comments yet