Impact
The flaw arises in a currently unknown function of the /mdiy/form/data/list endpoint within the ms-mdiy component of MingSoft MCMS. Triggering this function through crafted requests exposes sensitive data from the system, granting an adversary detailed internal information that should remain confidential. The weakness is modeled as an Information Exposure (CWE‑200) amplified by an authorization bypass or improper access control (CWE‑284), allowing an attacker to read data they normally would not be permitted to access.
Affected Systems
MingSoft: MCMS versions up to and including 3.0.6 are affected. This includes all installations of the product that have not applied any subsequent patch or reconfiguration to isolate the /mdiy/form/data/list route.
Risk and Exploitability
The vulnerability is scored with a CVSS Base score of 6.9, indicating moderate severity, but the absence of a publicly disclosed EPSS score means we cannot quantify current exploit probability. It is not listed in the CISA KEV catalog, but a publicly available exploit does exist and the description confirms that remote attackers can initiate the attack. Because the attacker can trigger this from an external network, the potential for coverage against multiple instances is significant. Mitigation is urgent to avoid unintended data leakage.
OpenCVE Enrichment