Executive brief
MCMS (MingSoft CMS) is a content management system used to build and manage websites. Versions 6.1.1 through 6.2.1 contain a SQL injection flaw in the custom model import feature that allows authenticated attackers to execute arbitrary SQL commands. An attacker with import permissions could read sensitive database information, modify tables, or escalate their database privileges.
Technical details
The vulnerability exists in the custom model/form import endpoint (/ms/mdiy/form/importJson.do) which passes attacker-controlled SQL from the modelJson.sql field directly to JdbcTemplate.execute() after incomplete validation. Although the code attempts to restrict the first SQL statement to CREATE/ALTER TABLE operations, a keyword-based filter can be bypassed using CREATE TABLE AS SELECT statements combined with specific SQL constructs. The flaw requires authentication and appropriate permissions (mdiy:form:importJson), but allows extraction of arbitrary database schema information and data exfiltration via subsequent queries to the form data endpoint.
Affected products
- MingSoft MCMS 6.1.1, 6.2.0, 6.2.1
Timeline
- 2026-08-27: disclosed
- 2026-09-22: advisory