SQL Injection Vulnerability in Feng Office by Fengoffice
CVE-2026-90496

5.1MEDIUM

Key Information:

Vendor

Fengoffice

Vendor
CVE Published:
13 September 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-90496?

A vulnerability exists in Feng Office affecting versions up to 3.11.13.11, particularly in the function responsible for updating system module order. This flaw, located in MoreController.class.php, allows for SQL injection through manipulated arguments. An attacker can exploit this vulnerability remotely to execute unauthorized SQL commands, potentially compromising sensitive data. The vulnerability details were disclosed publicly, and despite prior notification, there has been no response from the vendor regarding mitigation.

Affected Version(s)

Feng Office 3.11.13.0

Feng Office 3.11.13.1

Feng Office 3.11.13.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ciphersecuritylabs (VulDB User)
VulDB CNA Team
.