Impact
The vulnerability is an information disclosure flaw in MCMS version 6.1.1 that permits a remote attacker to obtain sensitive data by manipulating the source parameter. Classified as CWE‑200, it allows unauthorized disclosure of confidential information, thereby compromising the confidentiality of the system.
Affected Systems
Affected installations are MCMS v6.1.1. Vendor details are not publicly listed, but the product name indicates a content management system. No additional versions are mentioned, so only this exact version is confirmed to be vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of less than 1 percent shows a low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers can exploit the flaw remotely by sending crafted requests containing the source parameter from outside the network. No official patch is available, so mitigation must rely on workaround measures or network restrictions.
OpenCVE Enrichment