SQL Injection Vulnerability in Comsenz Discuz! Administration Panel
CVE-2026-105146

5.1MEDIUM

Key Information:

Vendor

Comsenz

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105146?

A vulnerability exists in the Comsenz Discuz! application affecting the Admin Medal Moderation component. Specifically, the modmedalsubmit function in the mod.php file is susceptible to SQL injection through manipulation of the delete argument. This flaw allows for remote exploitation, posing significant security risks if exploited. The vendor has been notified of this issue but has not responded, making it critical for users to take immediate precautions to secure their installations.

Affected Version(s)

Discuz! X5.0-20260801

Discuz! X5.0-20260820

Discuz! X5.0-20260910

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BlackSpdier (VulDB User)
VulDB CNA Team
.