Impact
An SQL injection flaw exists in Woltlab WCF version 6.2.4 and earlier, affecting the updateUserOptions method in UserEditor.class.php and the update action in UserAction.class.php. The vulnerability allows a remote actor to inject arbitrary SQL commands through crafted input, potentially giving full control over the underlying database. This weakness is a classic injection flaw (CWE‑89) and is reflected in the CVSS score of 9.8.
Affected Systems
The flaw is present in Woltlab WCF version 6.2.4 and all earlier releases, as referenced in the official community update and documentation links.
Risk and Exploitability
The exploit can be performed over standard web interfaces by sending specially crafted requests to the update endpoints. Although the EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, the very high CVSS score indicates a severe risk if an attacker can reach the affected endpoints. The likely attack vector is remote HTTP requests that exploit improper input sanitization or lack of parameterized queries.
OpenCVE Enrichment