Junglewise Threat Intelligence

CVE-2026-52203: MCMS SSRF in editor via source parameter

CVE-2026-52203 · Severity: info · CVSS 5 · Published 2026-07-17

Technologies: Mingsoft Mcms. Vendors: Mingsoft.

Executive brief

MCMS is a content management system used to build and manage websites. A security flaw in version 6.1.1 allows an attacker with very low-level access to trick the server into making unauthorized requests to internal or external systems. This could lead to the exposure of sensitive internal files or information that should not be publicly accessible.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in MCMS v.6.1.1 within the editor functionality. The vulnerability is located in the 'source' parameter of the '/ms/editor.do' endpoint when the 'action' parameter is set to 'catchimage'. A remote attacker with low-level privileges can exploit this by sending a crafted POST request containing a malicious URL in the 'source[]' parameter. This allows the attacker to force the server to perform GET requests to arbitrary internal or external locations, potentially leading to the disclosure of sensitive local files or internal network data.

Affected products

  • MCMS MCMS 6.1.1

Timeline

  • 2026-07-16: disclosed: Initial discovery and gist publication
  • 2026-07-17: advisory: CVE published to NVD dataset

References

Related threats