Impact
The vulnerability is a classic SQL injection in the MingSoft MCMS ms-mdiy component, specifically within the ModelDataImpl.queryDiyFormData method handling the formFields argument. A malicious user can supply crafted input that is directly incorporated into a database query, enabling unauthorized data read, modification, or potential command execution. The impact therefore is loss of data integrity and confidentiality of the underlying database contents.
Affected Systems
The affected product is MingSoft MCMS, with all versions up to and including 3.0.6 susceptible to this flaw. No other products or versions are listed as affected.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate severity, but the vulnerability is exploitable remotely and has been publicly disclosed, increasing the likelihood of real‑world attacks. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. Because the flaw can be triggered from an external network, organizations should consider it a high risk for any exposed installation and prioritize patching or mitigation promptly.
OpenCVE Enrichment