Impact
A SQL injection flaw exists in the Reorder Handlers component of Feng Office. By manipulating the modules/dims argument during a call to update_system_module_order or, an attacker can inject arbitrary SQL. The flaw allows reading or modifying data in the database, making it a direct database compromise vector. The vulnerability is a classic injection, corresponding to CWE‑74 and CWE‑89, and can be triggered remotely without authentication if the endpoint is publicly reachable.
Affected Systems
Feng Office 3.11.13.11 and earlier versions of the Feng Office application are affected. The vulnerable code resides in the MoreController controller of the Reorder Handlers component. Any installation running version 3.11.13.11 or earlier is susceptible; only versions beyond 3.11.13.11 are known to be patched.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is below 1 %, suggesting low exploitation probability as of the latest assessment, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, a public exploit has been released, and the flaw can be abused remotely by sending crafted modules/dims parameters. Attackers could gain unauthorized database access, but only if the endpoint is reachable by unauthenticated users or if additional authentication is bypassed.
OpenCVE Enrichment