{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/mcms/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-19355"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MCMS"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sqli","vulnerability-management"],"_cs_type":"advisory","_cs_vendors":["MingSoft"],"content_html":"\u003cp\u003eMingSoft MCMS (versions up to 3.0.6) is susceptible to a critical SQL injection vulnerability identified as CVE-2026-19355. The vulnerability resides within the ModelDataImpl.queryDiyFormData function of the ms-mdiy component. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request to the /mdiy/form/data/list.do endpoint, specifically injecting malicious SQL syntax into the 'formFields' argument. Successful exploitation enables unauthorized data extraction or modification within the underlying database. The vendor has been unresponsive to disclosure efforts, and proof-of-concept exploitation material is publicly available. Defenders should prioritize auditing traffic to the identified endpoint for anomalous SQL keywords or malformed input parameters.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated attacker to bypass authentication controls and execute arbitrary SQL commands. Depending on the database permissions of the MCMS application, this could lead to full database compromise, exfiltration of sensitive site data, or potential modification of administrative records, resulting in total loss of application integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web application logs for HTTP requests directed at /mdiy/form/data/list.do that contain SQL control characters (e.g., single quotes, comments, UNION, SELECT) within the formFields parameter.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) signatures designed to detect and block SQL injection attempts targeting the listed endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict access to the MCMS administrative and data-processing endpoints to trusted IP ranges until a patch is applied by the vendor or internal remediation is implemented.\u003c/li\u003e\n\u003cli\u003eEvaluate the application's database user permissions to ensure they follow the principle of least privilege, minimizing the blast radius in the event of successful injection.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-09T15:46:47Z","date_published":"2026-08-09T15:46:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mingsoft-mcms-sqli/","summary":"MingSoft MCMS versions up to 3.0.6 contain a remote SQL injection vulnerability in the ms-mdiy component, allowing unauthenticated attackers to manipulate the formFields argument to execute arbitrary database queries.","title":"SQL Injection Vulnerability in MingSoft MCMS","url":"https://feed.craftedsignal.io/briefs/2026-08-mingsoft-mcms-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - MCMS","version":"https://jsonfeed.org/version/1.1"}