Junglewise Threat Intelligence

CVE-2026-88416: MingSoft MCMS SQL injection in custom model import

CVE-2026-88416 · Severity: info · Published 2026-09-22

Technologies: Mingsoft Mcms. Vendors: Mingsoft.

Executive brief

MCMS (MingSoft CMS) is a content management system used to build and manage websites. Versions 6.1.1 through 6.2.1 contain a SQL injection flaw in the custom model import feature that allows authenticated attackers to execute arbitrary SQL commands. An attacker with import permissions could read sensitive database information, modify tables, or escalate their database privileges.

Technical details

The vulnerability exists in the custom model/form import endpoint (/ms/mdiy/form/importJson.do) which passes attacker-controlled SQL from the modelJson.sql field directly to JdbcTemplate.execute() after incomplete validation. Although the code attempts to restrict the first SQL statement to CREATE/ALTER TABLE operations, a keyword-based filter can be bypassed using CREATE TABLE AS SELECT statements combined with specific SQL constructs. The flaw requires authentication and appropriate permissions (mdiy:form:importJson), but allows extraction of arbitrary database schema information and data exfiltration via subsequent queries to the form data endpoint.

Affected products

  • MingSoft MCMS 6.1.1, 6.2.0, 6.2.1

Timeline

  • 2026-08-27: disclosed
  • 2026-09-22: advisory

References

Related threats