What is CVE-2026-19355?
A SQL injection vulnerability has been identified in MingSoft MCMS versions up to 3.0.6, affecting the ModelDataImpl.queryDiyFormData function in the /mdiy/form/data/list.do file of the ms-mdiy component. The flaw allows a remote attacker to manipulate the formFields argument, potentially compromising the database. Users are strongly advised to update their MCMS software to the latest version immediately.
Azərbaycanca: MingSoft MCMS-in 3.0.6 versiyasına qədər olan versiyalarında, ms-mdiy komponentində yerləşən /mdiy/form/data/list.do faylındakı ModelDataImpl.queryDiyFormData funksiyasında SQL injection zəifliyi aşkar edilib. Bu, uzaqdan hücum edən şəxsə formFields arqumentini manipulyasiya edərək verilənlər bazasına müdaxilə etməyə imkan verir. MCMS istifadəçilərinə təcili olaraq proqram təminatını ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of MingSoft MCMS are affected by the CVE-2026-19355 SQL injection vulnerability?
Versions of MingSoft MCMS up to 3.0.6 are affected.
How can an attacker exploit the CVE-2026-19355 vulnerability to compromise the database?
A remote attacker can manipulate the formFields argument in the ModelDataImpl.queryDiyFormData function within the /mdiy/form/data/list.do file to perform SQL injection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.