SQL Injection Vulnerability in Comsenz Discuz! Administration Panel
CVE-2026-105146
5.1MEDIUM
What is CVE-2026-105146?
A vulnerability exists in the Comsenz Discuz! application affecting the Admin Medal Moderation component. Specifically, the modmedalsubmit function in the mod.php file is susceptible to SQL injection through manipulation of the delete argument. This flaw allows for remote exploitation, posing significant security risks if exploited. The vendor has been notified of this issue but has not responded, making it critical for users to take immediate precautions to secure their installations.
Affected Version(s)
Discuz! X5.0-20260801
Discuz! X5.0-20260820
Discuz! X5.0-20260910
