Impact
The vulnerable function in the ms-mdiy component of MingSoft MCMS, exposed at /mdiy/form/get, permits an attacker to manipulate requests and trigger the disclosure of internal data that should be protected. The assembled data may include configuration details, user credentials, or other sensitive information, violating confidentiality principles. This weakness is classified as CWE‑200 for information disclosure and undermines access controls, aligning with CWE‑284.
Affected Systems
MingSoft MCMS versions prior to 3.0.6 are impacted, with the vulnerability located in the ms‑mdiy module of the CMS. Administrators using these versions must verify whether their deployment includes the /mdiy/form/get endpoint, which is the entry point for the exploitation.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability, and the associated EPSS score is not available, suggesting that no quantitative estimate of exploit likelihood is published. The vulnerability can be exploited remotely over the network by sending crafted requests to the affected endpoint, and a publicly available exploit has already been released. Because the flaw leads to unauthorized disclosure of potentially sensitive information and a remote attack vector, the risk to affected systems is significant, especially if the CMS is exposed to the Internet or an insecure internal network. Although the vulnerability is not listed in the CISA KEV catalog, its public exploit and moderate CVSS score warrant timely attention.
OpenCVE Enrichment