THREAT OPS › Threat News › [NVD] CVE-2026-19355 (HIGH 7.3) — A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be per
[NVD] CVE-2026-19355 (HIGH 7.3) — A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be per
CVE-2026-19355 CVSS: 7.3 HIGH Published: 2026-08-09T14:17:26.763
A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disc
Indicators of compromise
- CVE-2026-19355cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19355