{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/wuzhicms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wuzhicms:wuzhicms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-91848"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WuzhiCMS (\u003c= 4.1.0)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","vulnerability","web-application","ssrf","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["WuzhiCMS"],"content_html":"\u003cp\u003eA SQL injection vulnerability has been identified in WuzhiCMS in versions up to and including 4.1.0. The vulnerability resides within the article::getDataOfJson function, which is reachable via the endpoint /index.php?m=content\u0026amp;f=article\u0026amp;v=getDataOfJson. By manipulating the 'title' or 'master_table' arguments within an HTTP request, an unauthenticated remote attacker can inject arbitrary SQL commands. This flaw allows for potential unauthorized database access, including data exfiltration, modification, or deletion, depending on the privileges of the database user configured for the CMS. As of the disclosure date, the vulnerability is publicly documented with an available exploit, and the vendor has not yet addressed the issue. Organizations running affected WuzhiCMS instances should implement web application firewalls or similar controls to inspect incoming requests for SQL injection patterns targeting the specified endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-91848 allows remote, unauthenticated attackers to perform SQL injection. This can lead to complete compromise of the WuzhiCMS database, including the theft of sensitive user credentials, content, or system configuration data. The impact is significant for organizations relying on WuzhiCMS as it provides a direct vector for data exfiltration or potential persistence within the application layer.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to inspect and filter incoming HTTP POST/GET requests to /index.php where the query parameters 'm=content', 'f=article', and 'v=getDataOfJson' are present, specifically monitoring the 'title' and 'master_table' fields for SQL injection payloads.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests containing SQL keywords (e.g., SELECT, UNION, SLEEP, FROM) within the defined vulnerable parameters.\u003c/li\u003e\n\u003cli\u003eIf feasible, restrict access to the /index.php?m=content\u0026amp;f=article\u0026amp;v=getDataOfJson endpoint at the network or web server level until a patch is released by the vendor.\u003c/li\u003e\n\u003cli\u003eAudit database user privileges used by the WuzhiCMS application to follow the principle of least privilege, limiting the potential impact of a successful injection attack.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T15:52:07Z","date_published":"2026-09-15T17:42:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wuzhicms-sql-injection/","summary":"WuzhiCMS versions up to 4.1.0 contain a SQL injection vulnerability in the article::getDataOfJson function, allowing remote attackers to execute arbitrary SQL commands via the title or master_table parameters.","title":"SQL Injection Vulnerability in WuzhiCMS","url":"https://feed.craftedsignal.io/briefs/2026-09-wuzhicms-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - WuzhiCMS","version":"https://jsonfeed.org/version/1.1"}