Impact
This vulnerability allows an attacker to inject arbitrary SQL statements through the custom model/form import feature of MCMS. The injection can result in unauthorized data disclosure, modification, or deletion of database contents, compromising confidentiality and integrity of the entire system.
Affected Systems
The affected products are MCMS versions 6.1.1 through 6.2.1. No vendor information is specified, and the versions span the 6.x series released during the specified timeframe.
Risk and Exploitability
No exploitation probability data (EPSS) is available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. However, the potential for exploitation remains, especially if the import function is exposed to users beyond the core administrative staff. The lack of official remedial updates means that any use of the import feature represents a continuing risk until a patch or mitigation is applied.
OpenCVE Enrichment