CVE-2026-6562: medium-severity vulnerability in dameng100 muucmf
dameng100 muucmf index.html getListByPage sql injection
Published · Updated
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a manipulation of the argument keyword can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
dameng100 · muucmfpublic PoCs found — 1
cve_referencethinhneee.github.io/posts/muucmf-sqli/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — dameng100 muucmf
In the same product, most dangerous first.
CVE-2026-4848MEDIUMdameng100 muucmf list.html cross site scriptingEPSS 0.4%CVE-2026-4847MEDIUMdameng100 muucmf list.html cross site scriptingEPSS 0.4%CVE-2026-4846MEDIUMdameng100 muucmf autoReply.html cross site scriptingEPSS 0.4%CVE-2026-4845MEDIUMdameng100 muucmf index.html cross site scriptingEPSS 0.4%