Sceawere
Vulnerability Detail
CVE-2026-105146UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Discuz! X5 SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 4h ago
- Vendor
- Comsenz
- Product
- Discuz!
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. Affected by this issue is the function modmedalsubmit of the file upload/source/app/admin/child/medals/mod.php of the component Admin Medal Moderation. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-10-04T11:16:32.857Z",
"pubdate": "2026-10-04T11:16:32.857Z",
"executiveSummary": "A critical SQL injection vulnerability exists in the Admin Medal Moderation component of Comsenz Discuz! X5.0 (versions 20260801, 20260820, and 20260910).\nThe vulnerability resides within the modmedalsubmit function of the file upload/source/app/admin/child/medals/mod.php.\nImproper neutralization of special elements used in an SQL command allows an unauthenticated or unauthorized remote attacker to inject arbitrary SQL queries.\nSuccessful exploitation allows an attacker to manipulate, extract, or delete sensitive data from the underlying database, potentially leading to unauthorized administrative access or full system compromise.\nThe vulnerability is currently public, and the vendor has not provided a response or official patch, elevating the risk profile for organizations utilizing these specific software versions.\nThe attack is remotely exploitable, requiring no prior authentication if the endpoint is exposed, though it specifically targets administrative functionality.",
"technicalDetails": "The vulnerability is an Improper Neutralization of Special Elements used in an SQL Command, commonly referred to as SQL Injection (SQLi).\nThe issue is located in the function modmedalsubmit within the file upload/source/app/admin/child/medals/mod.php, which serves as a core component of the Admin Medal Moderation feature in Discuz! X5.0.\nThe root cause is the insecure handling of the 'delete' argument. The application fails to properly sanitize or parameterize the input provided to this argument before incorporating it into an SQL query string executed against the database.\nAn attacker can exploit this by crafting a malicious payload within the 'delete' argument. By injecting SQL syntax (such as UNION SELECT, SLEEP(), or Boolean-based inference strings), the attacker can bypass input validation mechanisms to force the application to execute unintended database operations.\nThe attack flow proceeds as follows: 1) The attacker targets the specific URL associated with the medal moderation submission endpoint. 2) The attacker intercepts or crafts an HTTP request containing a manipulated 'delete' parameter. 3) The application's backend processes the malicious input through the vulnerable function without proper validation. 4) The injected SQL code is executed by the database engine with the privileges assigned to the web application's database user.\nBecause the vulnerable function operates within the administrative scope of the application, the impact is severe. Exploitation can lead to unauthorized data exfiltration (including user credentials, personal information, or site configuration details), data modification, or deletion. Depending on the database configuration and permissions, an attacker might leverage database-specific features to gain further persistence or execute OS-level commands, leading to complete system takeover.\nThis vulnerability is classified as remote because the attack can be launched over the network against any internet-exposed instance of the affected Discuz! software. The existence of public exploit code lowers the barrier for entry for malicious actors, necessitating immediate defensive action in the absence of a vendor-supplied update."
}