{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/fengoffice/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fengoffice:feng_office:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90495"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Feng Office (\u003c= 3.11.13.11)"],"_cs_severities":["high"],"_cs_tags":["sqli","web-application","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Fengoffice"],"content_html":"\u003cp\u003eA critical SQL injection vulnerability exists in Feng Office versions up to 3.11.13.11, specifically affecting the 'findAll' function within 'application/models/CompanyWebsite.class.php'. This component, part of the Legacy API, fails to properly neutralize the 'auth' argument before incorporating it into database queries. Remote, unauthenticated attackers can exploit this flaw to inject arbitrary SQL commands, potentially leading to unauthorized data exfiltration, modification, or full compromise of the backend database. While public proof-of-concept exploits exist, the vendor has not responded to disclosure reports, leaving current installations at high risk. Detection engineers should focus on monitoring HTTP traffic for patterns associated with SQL injection attempts targeting the Legacy API endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to bypass authentication controls and execute arbitrary SQL queries against the application database. This can lead to the exposure of sensitive organizational data, including contact information and internal records, as well as the potential for administrative account takeovers or database-level system modifications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eReview web server logs for suspicious 'auth' parameter values containing SQL syntax characters (e.g., UNION, SELECT, --, ;) targeting the Legacy API path.\u003c/li\u003e\n\u003cli\u003eImplement WAF rules to sanitize or block input to the 'auth' parameter in the Legacy API module.\u003c/li\u003e\n\u003cli\u003eIf patching is unavailable due to lack of vendor response, restrict network access to the Legacy API component using edge firewall controls.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-13T05:24:27Z","date_published":"2026-09-13T05:24:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-feng-office-sqli/","summary":"Feng Office versions up to 3.11.13.11 are susceptible to remote SQL injection via the 'auth' parameter in the Legacy API component.","title":"Remote SQL Injection in Feng Office Legacy API","url":"https://feed.craftedsignal.io/briefs/2026-09-feng-office-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Fengoffice","version":"https://jsonfeed.org/version/1.1"}