What is CVE-2026-19357?
An information disclosure vulnerability has been identified in an unknown function of the /mdiy/form/get file within the ms-mdiy component of MingSoft MCMS up to version 3.0.6. The attack can be performed remotely and a public exploit is available, so immediate update to the latest version is recommended.
Azərbaycanca: MingSoft MCMS 3.0.6 versiyasına qədər olan sistemlərdə ms-mdiy komponentində yerləşən /mdiy/form/get faylındakı naməlum funksiya vasitəsilə məlumat sızması (information disclosure) zəifliyi aşkarlanıb. Uzaqdan həyata keçirilə bilən bu hücum üçün ictimai exploit mövcuddur, ona görə də sistemin dərhal son versiyaya yenilənməsi tövsiyə olunur.
FAQ2
Which versions of MingSoft MCMS are affected by CVE-2026-19357?
All versions up to 3.0.6 are affected.
Is there a public exploit available for CVE-2026-19357?
Yes, a public exploit is available, which is why an immediate update is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.