SQL Injection Vulnerability in Fengoffice Related to Timezone Setting
CVE-2025-5433
Key Information:
- Vendor
Fengoffice
- Status
- Vendor
- CVE Published:
- 2 June 2025
Badges
What is CVE-2025-5433?
A SQL injection vulnerability exists in Fengoffice versions including 3.5.1.5, specifically in the handling of the tz_offset parameter within /index.php?c=account&a=set_timezone. This flaw can be exploited remotely, allowing attackers to manipulate queries and potentially access or alter sensitive data. The exploit has been publicly disclosed, and despite early notification, the vendor has not addressed the issue, leaving systems vulnerable to possible attacks.
Affected Version(s)
Feng Office 3.5.1.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved