SQL Injection Vulnerability in Feng Office by Fengoffice
CVE-2026-90496
5.1MEDIUM
Key Information:
- Vendor
Fengoffice
- Status
- Vendor
- CVE Published:
- 13 September 2026
Badges
๐พ Exploit Exists
What is CVE-2026-90496?
A vulnerability exists in Feng Office affecting versions up to 3.11.13.11, particularly in the function responsible for updating system module order. This flaw, located in MoreController.class.php, allows for SQL injection through manipulated arguments. An attacker can exploit this vulnerability remotely to execute unauthorized SQL commands, potentially compromising sensitive data. The vulnerability details were disclosed publicly, and despite prior notification, there has been no response from the vendor regarding mitigation.
Affected Version(s)
Feng Office 3.11.13.0
Feng Office 3.11.13.1
Feng Office 3.11.13.2
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
ciphersecuritylabs (VulDB User)
VulDB CNA Team
