Junglewise Threat Intelligence

CVE-2026-88414: MCMS SQL injection in PageAction.verify endpoint

CVE-2026-88414 · Severity: critical · CVSS 9.8 · Published 2026-09-22

Technologies: Mingsoft Mcms. Vendors: Mingsoft.

Executive brief

MCMS is a content management system used to build and manage websites and web applications. A critical SQL injection vulnerability in the page verification endpoint allows authenticated attackers to extract, modify, or delete database contents and potentially execute arbitrary commands on the underlying database server. The vulnerability affects versions 6.1.1 through 6.2.1 and requires only valid authentication to exploit.

Technical details

The PageAction.verify endpoint (GET /ms/mdiy/page/verify.do) concatenates the user-controlled fieldName parameter unsafely into a SQL WHERE clause without proper parameterization. The endpoint lacks authorization checks that protect other methods in the same class, allowing any authenticated manager to access it. The vulnerability is compounded by a bypassable SQL injection filter that fails to block PREPARE/EXECUTE statements and hexadecimal-encoded payloads, combined with allowMultiQueries=true default configuration enabling stacked SQL queries for full database compromise.

Affected products

  • Mingsoft MCMS 6.1.1 through 6.2.1

Timeline

  • 2026-09-22: disclosed: Public disclosure on GitHub and NVD
  • 2026-08-25: other: Vulnerability discovered

References

Related threats