CVE-2026-90496
A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handlers. Performing a manipulation of the argument modules/dims results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.20%
- CWE
- CWE-89, CWE-74
- Published
- 2026-09-13
- Last modified
- 2026-09-16
Affected products
- Fengoffice Feng Office
- Fengoffice Feng Office
- Fengoffice Feng Office
- Fengoffice Feng Office
- Fengoffice Feng Office
- Fengoffice Feng Office
- Fengoffice Feng Office
- Fengoffice Feng Office
Weakness type
Related vulnerabilities
- CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection Vulnerability
- CVE-2026-67401 — A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTr
- CVE-2026-61667 — DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval
- CVE-2026-18658 — IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed
- CVE-2026-9163 — SQLi in GIS Informatics' GisLab Laboratory Management System
- CVE-2026-86460 — Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
- CVE-2026-82232 — Apache Syncope: SQL injection via sort parameter in Task search
- CVE-2026-77051 — Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search