SQL Injection Vulnerability in SoftNews Media Group DataLife Engine Search Module
CVE-2026-96604
Key Information:
- Vendor
Softnews Media Group
- Status
- Vendor
- CVE Published:
- 23 September 2026
Badges
What is CVE-2026-96604?
A significant SQL injection vulnerability exists in the Search Module of SoftNews Media Group's DataLife Engine version 18.0. This flaw is traced to the strip_data function within the search.php file, where improper handling of user input can lead to malicious exploitation. Attackers can execute unauthorized SQL statements remotely, potentially compromising the database integrity and gaining access to sensitive information. Publicly available exploits for this vulnerability increase its risk, as they allow malicious actors to leverage the weakness without requiring extensive technical skills. Early disclosure efforts to the vendor have gone unanswered, underscoring the urgency for users to take immediate protective measures.
Affected Version(s)
DataLife Engine 18.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
