Sceawere

Vulnerability Detail

CVE-2026-101018UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

XunruiCMS SQL Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
4h ago
Vendor
dayrui
Product
XunruiCMS
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the file dayrui/App/Member/Controllers/Admin/Home.php of the component Group Editing. This manipulation of the argument groupid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-09-28T10:16:42.137Z",
  "pubdate": "2026-09-28T10:16:42.137Z",
  "executiveSummary": "A critical SQL injection vulnerability exists in dayrui XunruiCMS versions up to 4.7.2, specifically within the Group Editing component.\nThe vulnerability originates from improper sanitization of the 'groupid' argument within the 'group_all_edit' function in 'dayrui/App/Member/Controllers/Admin/Home.php'.\nThis flaw allows remote, unauthenticated or authenticated attackers (depending on specific access controls surrounding the endpoint) to inject malicious SQL queries into the backend database.\nSuccessful exploitation grants an attacker the ability to bypass security controls, perform unauthorized data exfiltration, modify database contents, or potentially execute administrative operations.\nGiven that the exploit has been publicly disclosed and the vendor has remained unresponsive, the risk to installations is elevated, necessitating immediate defensive action.\nThis vulnerability highlights a failure to properly parameterize database queries or validate user-supplied input before it is processed by the database management system.",
  "technicalDetails": "The vulnerability is a SQL injection (SQLi) flaw located in the 'group_all_edit' function within the file 'dayrui/App/Member/Controllers/Admin/Home.php' in the XunruiCMS Member application.\nThe root cause is the insecure handling of the 'groupid' parameter. When the application processes a request to the 'group_all_edit' function, it takes the 'groupid' argument and incorporates it directly into a SQL query string without adequate sanitization, escaping, or the use of prepared statements.\nAn attacker can exploit this by crafting a malicious HTTP request (either GET or POST) where the 'groupid' parameter contains SQL payload syntax instead of the expected identifier. Because the input is treated as trusted data by the application's database layer, the injected SQL commands are executed by the underlying database management system.\nThe attack flow involves the attacker identifying the target endpoint. Upon sending a request containing the manipulated 'groupid', the application concatenates the malicious input into a backend SQL query. This manipulation changes the logic of the intended query, allowing the attacker to influence the structure and execution of the database statement.\nDepending on the configuration of the database and the application's query structure, this can lead to union-based SQL injection, error-based SQL injection, or blind SQL injection, enabling the retrieval of sensitive information from other tables within the database.\nThis vulnerability is remotely exploitable. The lack of validation on the 'groupid' argument allows for arbitrary SQL command execution, which could lead to full compromise of the database integrity and confidentiality. Since the vendor has not responded to the disclosure, no official patch is available to remediate this specific code path.\nPost-exploitation impact includes unauthorized access to sensitive application data, potential user account takeover, and in some database configurations, the ability to perform administrative actions, modify configurations, or execute operating system commands if the database user permissions are overly permissive."
}
CVE-2026-101018: XunruiCMS SQL Injection Vulnerability (MEDIUM Severity, CVSS: 4.7) | Sceawere