Description
An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.
Published: 2026-07-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an information disclosure flaw in MCMS version 6.1.1 that permits a remote attacker to obtain sensitive data by manipulating the source parameter. Classified as CWE‑200, it allows unauthorized disclosure of confidential information, thereby compromising the confidentiality of the system.

Affected Systems

Affected installations are MCMS v6.1.1. Vendor details are not publicly listed, but the product name indicates a content management system. No additional versions are mentioned, so only this exact version is confirmed to be vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score of less than 1 percent shows a low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers can exploit the flaw remotely by sending crafted requests containing the source parameter from outside the network. No official patch is available, so mitigation must rely on workaround measures or network restrictions.

Generated by OpenCVE AI on August 3, 2026 at 02:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict network access to the MCMS instance or the specific endpoint that processes the source parameter, limiting it to trusted IP ranges or internal network segments.
  • If a patch cannot be applied immediately, disable or remove the source parameter functionality using application configuration or code changes to prevent information disclosure.
  • Implement logging and monitoring for suspicious usage of the source parameter to detect potential exploitation attempts.

Generated by OpenCVE AI on August 3, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title MCMS v6.1.1 Source Parameter Leaks Sensitive Information

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title MCMS v6.1.1 Source Parameter Leaks Sensitive Information

Sat, 25 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Source Parameter in MCMS v6.1.1

Wed, 22 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Source Parameter in MCMS v6.1.1

Mon, 20 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-20T17:53:09.054Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52203

cve-icon Vulnrichment

Updated: 2026-07-20T17:53:03.280Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor