Description
A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of the argument auth leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in Feng Office versions 3.11.13.11 and earlier within the Contacts::instance->findAll function of CompanyWebsite.class.php in the Legacy API component. An attacker can supply a crafted auth parameter that is not properly validated, causing the application to execute arbitrary SQL statements. The injection can be used to read, modify or delete sensitive data stored in the application’s database.

Affected Systems

All installations of Feng Office running versions 3.11.13.11 or earlier are vulnerable. The flaw resides in the Legacy API component and affects the CompanyWebsite.class.php model linked to contact management within Feng Office.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. While a public exploit exists, the EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote, targeting the Legacy API endpoint, and requires sending a crafted payload that manipulates the auth parameter. Even with the current exposure metrics, the potential damage to the confidentiality and integrity of the database warrants urgent attention.

Generated by OpenCVE AI on September 15, 2026 at 17:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy a patched or newer version of Feng Office that removes the input validation flaw in CompanyWebsite.findAll.
  • Restrict external access to the Legacy API endpoint through firewall rules or network segmentation to limit the attack surface.
  • Implement strict input validation and parameterized queries for the auth argument within the affected function to prevent SQL injection.

Generated by OpenCVE AI on September 15, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of the argument auth leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Fengoffice Feng Office Legacy API CompanyWebsite.class.php instance->findAll sql injection
First Time appeared Fengoffice
Fengoffice feng Office
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:fengoffice:feng_office:*:*:*:*:*:*:*:*
Vendors & Products Fengoffice
Fengoffice feng Office
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Fengoffice Feng Office
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T18:07:48.002Z

Reserved: 2026-09-12T08:16:06.602Z

Link: CVE-2026-90495

cve-icon Vulnrichment

Updated: 2026-09-14T18:06:05.374Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T04:17:15.717

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')