{"id":"CVE-2026-88414","published":"2026-09-22T19:16:55.207","lastModified":"2026-09-26T00:16:37.643","description":"MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do).","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://github.com/15536818056/CVE/issues/1","tags":[]},{"url":"https://github.com/15536818056/CVE/issues/1","tags":[]}],"exploitRefs":[{"url":"https://github.com/15536818056/CVE/issues/1","tags":[]},{"url":"https://github.com/15536818056/CVE/issues/1","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw is a SQL injection vulnerability in the PageAction.verify endpoint of MCMS 6.1.1 through 6.2.1, allowing attackers to execute arbitrary SQL commands and potentially gain full control over the database.","exploitability":"Exploitation is relatively straightforward given the critical nature of the vulnerability, requiring only access to the affected endpoint via a GET request.","blast_radius":"If exploited, this vulnerability could result in complete database compromise, leading to data theft, corruption, or loss.","remediation":"Upgrade to MCMS 6.2.2 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["sql-injection","web","database"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:50:00.107Z"}}