Impact
The vulnerability exists in Feng Office versions 3.11.13.11 and earlier within the Contacts::instance->findAll function of CompanyWebsite.class.php in the Legacy API component. An attacker can supply a crafted auth parameter that is not properly validated, causing the application to execute arbitrary SQL statements. The injection can be used to read, modify or delete sensitive data stored in the application’s database.
Affected Systems
All installations of Feng Office running versions 3.11.13.11 or earlier are vulnerable. The flaw resides in the Legacy API component and affects the CompanyWebsite.class.php model linked to contact management within Feng Office.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. While a public exploit exists, the EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote, targeting the Legacy API endpoint, and requires sending a crafted payload that manipulates the auth parameter. Even with the current exposure metrics, the potential damage to the confidentiality and integrity of the database warrants urgent attention.
OpenCVE Enrichment