Description
SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection leading to database compromise
Action: Immediate Patch
AI Analysis

Impact

An SQL injection flaw exists in Woltlab WCF version 6.2.4 and earlier, affecting the updateUserOptions method in UserEditor.class.php and the update action in UserAction.class.php. The vulnerability allows a remote actor to inject arbitrary SQL commands through crafted input, potentially giving full control over the underlying database. This weakness is a classic injection flaw (CWE‑89) and is reflected in the CVSS score of 9.8.

Affected Systems

The flaw is present in Woltlab WCF version 6.2.4 and all earlier releases, as referenced in the official community update and documentation links.

Risk and Exploitability

The exploit can be performed over standard web interfaces by sending specially crafted requests to the update endpoints. Although the EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, the very high CVSS score indicates a severe risk if an attacker can reach the affected endpoints. The likely attack vector is remote HTTP requests that exploit improper input sanitization or lack of parameterized queries.

Generated by OpenCVE AI on September 21, 2026 at 05:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Woltlab WCF to the latest patched version (e.g., 6.2.5 or newer).
  • If an upgrade cannot be performed immediately, configure the database user used by the application with the least privileges required, avoiding full DBA rights that would allow arbitrary SQL execution.
  • Ensure that all user input reaching the updateUserOptions or update actions is validated or processed via parameterized queries to eliminate injection vectors.
  • Implement logging and alerting for anomalous database queries or authentication failures to detect potential exploitation attempts.

Generated by OpenCVE AI on September 21, 2026 at 05:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Remote SQL Injection in Woltlab WCF User Update Functions

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Woltlab
Woltlab wcf
Vendors & Products Woltlab
Woltlab wcf

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:21:39.257Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52630

cve-icon Vulnrichment

Updated: 2026-09-14T16:21:34.622Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T20:17:13.920

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-52630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:15:09Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')