Description
A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handlers. Performing a manipulation of the argument modules/dims results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Database Compromise
Action: Patch
AI Analysis

Impact

A SQL injection flaw exists in the Reorder Handlers component of Feng Office. By manipulating the modules/dims argument during a call to update_system_module_order or, an attacker can inject arbitrary SQL. The flaw allows reading or modifying data in the database, making it a direct database compromise vector. The vulnerability is a classic injection, corresponding to CWE‑74 and CWE‑89, and can be triggered remotely without authentication if the endpoint is publicly reachable.

Affected Systems

Feng Office 3.11.13.11 and earlier versions of the Feng Office application are affected. The vulnerable code resides in the MoreController controller of the Reorder Handlers component. Any installation running version 3.11.13.11 or earlier is susceptible; only versions beyond 3.11.13.11 are known to be patched.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score is below 1 %, suggesting low exploitation probability as of the latest assessment, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, a public exploit has been released, and the flaw can be abused remotely by sending crafted modules/dims parameters. Attackers could gain unauthorized database access, but only if the endpoint is reachable by unauthenticated users or if additional authentication is bypassed.

Generated by OpenCVE AI on September 15, 2026 at 17:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Feng Office to a version newer than 3.11.13.11 to eliminate the vulnerability.
  • If an upgrade is not possible immediately, restrict the MoreController endpoint to authenticated sessions only and input validation or a web‑application firewall rule that blocks unexpected SQL syntax in the modules/dims parameter to prevent injection.
  • If the database user used by the application has excessive privileges, adjust it to the minimum required (e.g., remove write permissions if not needed) to reduce the impact of potential injection.

Generated by OpenCVE AI on September 15, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handlers. Performing a manipulation of the argument modules/dims results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Fengoffice Feng Office Reorder Handlers MoreController.class.php update_dimension_order sql injection
First Time appeared Fengoffice
Fengoffice feng Office
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:fengoffice:feng_office:*:*:*:*:*:*:*:*
Vendors & Products Fengoffice
Fengoffice feng Office
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Fengoffice Feng Office
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T13:56:18.343Z

Reserved: 2026-09-12T08:16:10.094Z

Link: CVE-2026-90496

cve-icon Vulnrichment

Updated: 2026-09-16T13:56:11.951Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T06:16:25.750

Modified: 2026-09-16T14:17:13.340

Link: CVE-2026-90496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:00:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')