Impact
A flaw in the Admin Medal Moderation module of Comsenz Discuz! allows an attacker to manipulate the delete argument and inject arbitrary SQL into queries. The vulnerability is a classic injection issue that can lead to unauthorized data disclosure or modification, potentially exposing sensitive user information or enabling further attacks on the underlying database. The flaw is limited to this administrative functionality and does not provide code execution but can alter data integrity and confidentiality.
Affected Systems
Comsenz Discuz! versions X5.0-20260801, X5.0-20260820, and X5.0-20260910 are affected. The vulnerability resides specifically in the modmedalsubmit function within upload/source/app/admin/child/medals/mod.php of the Admin Medal Moderation component.
Risk and Exploitability
The CVSS base score of 5.1 indicates a moderate impact, and the EPSS score is unavailable, meaning the historic exploitation probability cannot be assessed; however, the exploit is publicly available, implying that an attacker could deploy it with relative ease. The vulnerability is not listed in CISA’s KEV catalog. Attackers can reach the vulnerable interface remotely, likely by accessing the admin URLs from an external network, which means an unauthenticated or low‑privilege attacker could potentially craft malicious input if the admin panel is exposed.
OpenCVE Enrichment