Executive brief
MCMS is a content management system used to build and manage websites and web applications. A critical SQL injection vulnerability in the page verification endpoint allows authenticated attackers to extract, modify, or delete database contents and potentially execute arbitrary commands on the underlying database server. The vulnerability affects versions 6.1.1 through 6.2.1 and requires only valid authentication to exploit.
Technical details
The PageAction.verify endpoint (GET /ms/mdiy/page/verify.do) concatenates the user-controlled fieldName parameter unsafely into a SQL WHERE clause without proper parameterization. The endpoint lacks authorization checks that protect other methods in the same class, allowing any authenticated manager to access it. The vulnerability is compounded by a bypassable SQL injection filter that fails to block PREPARE/EXECUTE statements and hexadecimal-encoded payloads, combined with allowMultiQueries=true default configuration enabling stacked SQL queries for full database compromise.
Affected products
- Mingsoft MCMS 6.1.1 through 6.2.1
Timeline
- 2026-09-22: disclosed: Public disclosure on GitHub and NVD
- 2026-08-25: other: Vulnerability discovered