AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T14:17:26.930Z and has not been modified since then. This vulnerability, identified in MingSoft MCMS up to version 3.0.6, impacts an unknown function of the file /mdiy/form/data/list within the ms-mdiy component. The manipulation leads to information disclosure, and the attack can be initiated rem [truncated]
CVE-2026-19355 is a SQL injection vulnerability in MingSoft MCMS up to version 3.0.6, affecting the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do in the ms-mdiy component. The vulnerability allows remote attackers to execute SQL injection attacks by manipulating the argument formFields. The CVSS score is 5.5, indicating a medium severity vulnerability. Administrators and user [truncated]