CWE-74
DiscouragedImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Abstraction: Class · Status: Incomplete
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
10250 vulnerabilities reference this CWE, most recent first.
CVE-2026-95925 (GCVE-0-2026-95925)
Vulnerability from cvelistv5 – Published: 2026-09-23 01:00 – Updated: 2026-09-23 14:56 X_Freeware| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408547 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408547/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-95925 | third-party-advisory |
| https://vuldb.com/submit/953304 | third-party-advisory |
| https://github.com/huliangjia/cve/issues/5 | exploitissue-tracking |
| https://www.sourcecodester.com/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| SourceCodester | Online Reviewer Management System |
Affected:
1.0
cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95925",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T14:56:24.862926Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T14:56:34.625Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*"
],
"product": "Online Reviewer Management System",
"vendor": "SourceCodester",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "huliangjia (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T01:00:12.395Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408547 | SourceCodester Online Reviewer Management System btn_functions.php update sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408547"
},
{
"name": "VDB-408547 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408547/cti"
},
{
"name": "CVE-2026-95925 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-95925"
},
{
"name": "Submit #953304 | SourceCodester Online Reviewer Management System using PHP/MySQL /reviewer_0/admins/assessments/databank/btn_functions.php?action=update 1.0 SQL Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/953304"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/huliangjia/cve/issues/5"
},
{
"tags": [
"product"
],
"url": "https://www.sourcecodester.com/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-22T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-22T19:22:39.000Z",
"value": "VulDB entry last update"
}
],
"title": "SourceCodester Online Reviewer Management System btn_functions.php update sql injection",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-95925",
"datePublished": "2026-09-23T01:00:12.395Z",
"dateReserved": "2026-09-22T17:17:22.731Z",
"dateUpdated": "2026-09-23T14:56:34.625Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95924 (GCVE-0-2026-95924)
Vulnerability from cvelistv5 – Published: 2026-09-23 00:45 – Updated: 2026-09-26 00:16 X_Freeware| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408546 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408546/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-95924 | third-party-advisory |
| https://vuldb.com/submit/953303 | third-party-advisory |
| https://github.com/huliangjia/cve/issues/4 | exploitissue-tracking |
| https://www.sourcecodester.com/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| SourceCodester | Online Reviewer Management System |
Affected:
1.0
cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95924",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-26T00:16:21.704117Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T00:16:33.421Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*"
],
"product": "Online Reviewer Management System",
"vendor": "SourceCodester",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "huliangjia (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T00:45:13.242Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408546 | SourceCodester Online Reviewer Management System btn_functions.php add sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408546"
},
{
"name": "VDB-408546 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408546/cti"
},
{
"name": "CVE-2026-95924 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-95924"
},
{
"name": "Submit #953303 | SourceCodester Online Reviewer Management System using PHP/MySQL /reviewer_0/admins/assessments/databank/btn_functions.php?action=add 1.0 SQL Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/953303"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/huliangjia/cve/issues/4"
},
{
"tags": [
"product"
],
"url": "https://www.sourcecodester.com/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-22T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-22T19:22:35.000Z",
"value": "VulDB entry last update"
}
],
"title": "SourceCodester Online Reviewer Management System btn_functions.php add sql injection",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-95924",
"datePublished": "2026-09-23T00:45:13.242Z",
"dateReserved": "2026-09-22T17:17:19.270Z",
"dateUpdated": "2026-09-26T00:16:33.421Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95868 (GCVE-0-2026-95868)
Vulnerability from cvelistv5 – Published: 2026-09-23 00:00 – Updated: 2026-09-23 16:22| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408542 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408542/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-95868 | third-party-advisory |
| https://vuldb.com/submit/953178 | third-party-advisory |
| https://github.com/AdithyaYelloju/Restaurant-Mana… | exploitissue-tracking |
| https://github.com/AdithyaYelloju/Restaurant-Mana… | product |
| Vendor | Product | Version | |
|---|---|---|---|
| AdithyaYelloju | Restaurant-Management-System |
Affected:
7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c
cpe:2.3:a:adithyayelloju:restaurant-management-system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95868",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T16:22:04.514448Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T16:22:12.573Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://vuldb.com/submit/953178"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:adithyayelloju:restaurant-management-system:*:*:*:*:*:*:*:*"
],
"modules": [
"Search Form"
],
"product": "Restaurant-Management-System",
"vendor": "AdithyaYelloju",
"versions": [
{
"status": "affected",
"version": "7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "jamesjie (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the function mysqli_query of the file admin/display_menu.php of the component Search Form. This manipulation of the argument s1 causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T00:00:18.248Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408542 | AdithyaYelloju Restaurant-Management-System Search Form display_menu.php mysqli_query sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408542"
},
{
"name": "VDB-408542 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408542/cti"
},
{
"name": "CVE-2026-95868 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-95868"
},
{
"name": "Submit #953178 | AdithyaYelloju Restaurant-Management-System 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c SQL Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/953178"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/4"
},
{
"tags": [
"product"
],
"url": "https://github.com/AdithyaYelloju/Restaurant-Management-System/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-22T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-22T19:08:22.000Z",
"value": "VulDB entry last update"
}
],
"title": "AdithyaYelloju Restaurant-Management-System Search Form display_menu.php mysqli_query sql injection",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-95868",
"datePublished": "2026-09-23T00:00:18.248Z",
"dateReserved": "2026-09-22T17:03:15.217Z",
"dateUpdated": "2026-09-23T16:22:12.573Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95833 (GCVE-0-2026-95833)
Vulnerability from cvelistv5 – Published: 2026-09-22 23:45 – Updated: 2026-09-23 14:34 X_Freeware| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408524 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408524/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-95833 | third-party-advisory |
| https://vuldb.com/submit/953126 | third-party-advisory |
| https://github.com/ltranquility/submit_repository… | exploitissue-tracking |
| https://itsourcecode.com/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| itsourcecode | Leave Management System |
Affected:
1.0
cpe:2.3:a:itsourcecode:leave_management_system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95833",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T14:30:39.161439Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T14:34:00.811Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:itsourcecode:leave_management_system:*:*:*:*:*:*:*:*"
],
"product": "Leave Management System",
"vendor": "itsourcecode",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "CyberXSec (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A weakness has been identified in itsourcecode Leave Management System 1.0. Impacted is an unknown function of the file /module/leavetype/index.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T23:45:11.958Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408524 | itsourcecode Leave Management System index.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408524"
},
{
"name": "VDB-408524 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408524/cti"
},
{
"name": "CVE-2026-95833 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-95833"
},
{
"name": "Submit #953126 | itsourcecode Leave Management System V1.0 SQL Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/953126"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/ltranquility/submit_repository/issues/16"
},
{
"tags": [
"product"
],
"url": "https://itsourcecode.com/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-22T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-22T18:35:23.000Z",
"value": "VulDB entry last update"
}
],
"title": "itsourcecode Leave Management System index.php sql injection",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-95833",
"datePublished": "2026-09-22T23:45:11.958Z",
"dateReserved": "2026-09-22T16:30:18.762Z",
"dateUpdated": "2026-09-23T14:34:00.811Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95832 (GCVE-0-2026-95832)
Vulnerability from cvelistv5 – Published: 2026-09-25 12:54 – Updated: 2026-09-25 15:30 X_Open Source- CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
| URL | Tags |
|---|---|
| https://github.com/kovidgoyal/kitty/commit/03fbda… | patch |
| https://github.com/kovidgoyal/kitty/commit/57bb14… | related |
| https://github.com/kovidgoyal/kitty/releases/tag/… | release-notes |
| https://www.cve.org/CVERecord?id=CVE-2026-54057 | related |
| https://secur0.com/en/cna/cve-list/cve-2026-95832… | third-party-advisorytechnical-description |
| Vendor | Product | Version | |
|---|---|---|---|
| Kovid Goyal | kitty |
Affected:
0.47.3 , < 0.49.0
(semver)
cpe:2.3:a:kovidgoyal:kitty:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95832",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T15:29:56.732664Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T15:30:58.146Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "kitty",
"programFiles": [
"kitty/window.py",
"kitty/screen.c"
],
"repo": "https://github.com/kovidgoyal/kitty",
"vendor": "Kovid Goyal",
"versions": [
{
"lessThan": "0.49.0",
"status": "affected",
"version": "0.47.3",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:kovidgoyal:kitty:*:*:*:*:*:*:*:*",
"versionEndExcluding": "0.49.0",
"versionStartIncluding": "0.47.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriel Machado Tavares"
},
{
"lang": "en",
"type": "analyst",
"value": "Cristian Fern\u00e1ndez Cornejo"
},
{
"lang": "en",
"type": "analyst",
"value": "Xo\u00e1n M. Otero Jorge"
},
{
"lang": "en",
"type": "coordinator",
"value": "Secur0 CNA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Kovid Goyal"
}
],
"datePublic": "2026-09-25T12:45:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in the user\u0027s shell, because \u003ccode\u003ecolor_control()\u003c/code\u003e in \u003ccode\u003ekitty/window.py\u003c/code\u003e answers a query for an unrecognised field name by placing that field name into the reply, and \u003ccode\u003ewrite_escape_code_to_child()\u003c/code\u003e in \u003ccode\u003ekitty/screen.c\u003c/code\u003e then writes the reply to the pseudoterminal master, where it is not distinguishable from input typed by the user, without neutralising it for the shell that reads it. The payload is reduced to printable ASCII before the field name is echoed, which is the restriction introduced in 0.47.3 as the fix for CVE-2026-54057, and the record and field separators \u003ccode\u003e;\u003c/code\u003e and \u003ccode\u003e=\u003c/code\u003e are consumed as delimiters, but every other printable character survives, which is sufficient to compose a shell command. A newline is available from \u003ccode\u003ehandle_remote_ssh()\u003c/code\u003e in \u003ccode\u003ekitty/window.py\u003c/code\u003e, which writes the bytes yielded by \u003ccode\u003eget_ssh_data()\u003c/code\u003e in \u003ccode\u003ekittens/ssh/utils.py\u003c/code\u003e, the first of which begin with a newline, to the pseudoterminal master before any credential carried in the request is checked. The reply is framed as an OSC sequence carrying the escape code number, the field name, and the literal value \u003ccode\u003e?\u003c/code\u003e. This results in execution of an attacker-chosen command with the privileges of the user running the terminal."
}
],
"value": "Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in the user\u0027s shell, because color_control() in kitty/window.py answers a query for an unrecognised field name by placing that field name into the reply, and write_escape_code_to_child() in kitty/screen.c then writes the reply to the pseudoterminal master, where it is not distinguishable from input typed by the user, without neutralising it for the shell that reads it. The payload is reduced to printable ASCII before the field name is echoed, which is the restriction introduced in 0.47.3 as the fix for CVE-2026-54057, and the record and field separators ; and = are consumed as delimiters, but every other printable character survives, which is sufficient to compose a shell command. A newline is available from handle_remote_ssh() in kitty/window.py, which writes the bytes yielded by get_ssh_data() in kittens/ssh/utils.py, the first of which begin with a newline, to the pseudoterminal master before any credential carried in the request is checked. The reply is framed as an OSC sequence carrying the escape code number, the field name, and the literal value ?. This results in execution of an attacker-chosen command with the privileges of the user running the terminal."
}
],
"exploits": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eCode execution has been demonstrated via exploitation of this vulnerability.\u003c/p\u003e"
}
],
"value": "Code execution has been demonstrated via exploitation of this vulnerability."
}
],
"impacts": [
{
"capecId": "CAPEC-248",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-248 Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T12:54:25.930Z",
"orgId": "4daa8cea-433a-44bd-9456-53b127fc289a",
"shortName": "Secur0"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://github.com/kovidgoyal/kitty/commit/03fbdad855490470233954bc810e517027e5e640"
},
{
"tags": [
"related"
],
"url": "https://github.com/kovidgoyal/kitty/commit/57bb144d96c0f9d48a2b0a6d43c9a23d2a091cbf"
},
{
"tags": [
"release-notes"
],
"url": "https://github.com/kovidgoyal/kitty/releases/tag/v0.49.0"
},
{
"tags": [
"related"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-54057"
},
{
"tags": [
"third-party-advisory",
"technical-description"
],
"url": "https://secur0.com/en/cna/cve-list/cve-2026-95832-kitty-color-control-command-execution"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Upgrade to kitty 0.49.0 or later."
}
],
"value": "Upgrade to kitty 0.49.0 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"tags": [
"x_open-source"
],
"title": "Reflected unknown field names in the kitty colour control escape code allow command execution in the user\u0027s shell",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "4daa8cea-433a-44bd-9456-53b127fc289a",
"assignerShortName": "Secur0",
"cveId": "CVE-2026-95832",
"datePublished": "2026-09-25T12:54:25.930Z",
"dateReserved": "2026-09-22T16:30:06.022Z",
"dateUpdated": "2026-09-25T15:30:58.146Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95829 (GCVE-0-2026-95829)
Vulnerability from cvelistv5 – Published: 2026-09-22 23:15 – Updated: 2026-09-26 00:13 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408522 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408522/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-95829 | third-party-advisory |
| https://vuldb.com/submit/897248 | third-party-advisory |
| https://github.com/TDuckCloud/tduck-survey-form/c… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| TDuckCloud | tduck-platform |
Affected:
5.0
Affected: 5.1 Affected: 5.2 Affected: 5.3 cpe:2.3:a:tduckcloud:tduck-platform:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95829",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-26T00:13:37.993491Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T00:13:49.255Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:tduckcloud:tduck-platform:*:*:*:*:*:*:*:*"
],
"modules": [
"Pagination Inner Interceptor"
],
"product": "tduck-platform",
"vendor": "TDuckCloud",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"status": "affected",
"version": "5.1"
},
{
"status": "affected",
"version": "5.2"
},
{
"status": "affected",
"version": "5.3"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "p5092 (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB Vulnerability Moderation Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner Interceptor. The manipulation of the argument orders[0].column leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is ea7f0fae7cb0fd998a3284c11addce689350cd69. It is suggested to install a patch to address this issue."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T23:15:10.573Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408522 | TDuckCloud tduck-platform Pagination Inner Interceptor MybatisPlusConfig.java PaginationInnerInterceptor.concatOrderBy sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408522"
},
{
"name": "VDB-408522 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408522/cti"
},
{
"name": "CVE-2026-95829 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-95829"
},
{
"name": "Submit #897248 | TDuckCloud tduck-platform 5.1,master \u003c ea7f0fae7cb0fd998a3284c11addce689350cd69 SQL Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/897248"
},
{
"tags": [
"patch"
],
"url": "https://github.com/TDuckCloud/tduck-survey-form/commit/ea7f0fae7cb0fd998a3284c11addce689350cd69"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-22T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-22T18:23:07.000Z",
"value": "VulDB entry last update"
}
],
"title": "TDuckCloud tduck-platform Pagination Inner Interceptor MybatisPlusConfig.java PaginationInnerInterceptor.concatOrderBy sql injection",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-95829",
"datePublished": "2026-09-22T23:15:10.573Z",
"dateReserved": "2026-09-22T16:17:27.381Z",
"dateUpdated": "2026-09-26T00:13:49.255Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95819 (GCVE-0-2026-95819)
Vulnerability from cvelistv5 – Published: 2026-09-22 22:00 – Updated: 2026-09-23 14:34| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408519 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408519/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-95819 | third-party-advisory |
| https://vuldb.com/submit/897167 | third-party-advisory |
| https://github.com/yingxiujie/cve/issues/9 | exploitissue-tracking |
| Vendor | Product | Version | |
|---|---|---|---|
| anirbandutta9 | College-Notes-Gallery |
Affected:
8c1cf3d98f30982d069c88ca172612c001eb39f6
cpe:2.3:a:anirbandutta9:college-notes-gallery:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95819",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T14:30:52.345857Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T14:34:48.696Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:anirbandutta9:college-notes-gallery:*:*:*:*:*:*:*:*"
],
"product": "College-Notes-Gallery",
"vendor": "anirbandutta9",
"versions": [
{
"status": "affected",
"version": "8c1cf3d98f30982d069c88ca172612c001eb39f6"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "yingxiujie (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument user/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T22:00:12.254Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408519 | anirbandutta9 College-Notes-Gallery login.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408519"
},
{
"name": "VDB-408519 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408519/cti"
},
{
"name": "CVE-2026-95819 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-95819"
},
{
"name": "Submit #897167 | College-Notes-Gallery v1.0.0 SQL Injection leading to Authentication Bypass Vulnerability",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/897167"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/yingxiujie/cve/issues/9"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-22T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-22T18:16:07.000Z",
"value": "VulDB entry last update"
}
],
"title": "anirbandutta9 College-Notes-Gallery login.php sql injection",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-95819",
"datePublished": "2026-09-22T22:00:12.254Z",
"dateReserved": "2026-09-22T16:10:54.883Z",
"dateUpdated": "2026-09-23T14:34:48.696Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95806 (GCVE-0-2026-95806)
Vulnerability from cvelistv5 – Published: 2026-09-22 15:09 – Updated: 2026-09-22 15:54| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/08fa755b6 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-22 15:01 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/08fa755b6.patch
f4fc3223e642… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
08fa755b6363
|
chg: [internal] Unregister the phar stream wrapper in the | f4fc3223e642… |
Fix summary
The phar stream wrapper is unregistered via stream_wrapper_unregister('phar') at the top of both the web and console entry points, before any framework bootstrap or application code executes. Because no MISP component, CakePHP, or runtime library requires the phar wrapper, removing it eliminates the implicit unserialize() sink and the directory-like phar archive behavior without functional impact. This closes the deserialization and code-execution primitive application-wide, independent of whether individual callers validate their path arguments.
Patch summary
Two files are modified. In app/Console/cake.php and app/webroot/index.php, a 14-line block is inserted immediately after the file header comment and before any existing logic. The block checks whether 'phar' is present in stream_get_wrappers() and, if so, calls stream_wrapper_unregister('phar'). A docblock comment explains the security rationale: the wrapper turns filesystem calls on caller-influenced paths into unserialize() sinks and allows a relocated application root to reach code inside an uploaded file. No other code is changed; the total diff is 28 insertions across the two files.
CVSS rationale
AV:N: The vulnerability is reachable through the web entry point (app/webroot/index.php), making it network-accessible. AC:H: Exploitation requires crafting a valid phar archive with a malicious serialized payload and identifying a code path where a caller-influenced filesystem argument resolves to that archive; the commit describes this as an 'argument-injection exploit,' implying non-trivial path manipulation. AT:N: No specific attack-target conditions are indicated. PR:L: MISP is a threat-intelligence platform that typically requires authenticated access; the commit references 'the web user' context, suggesting the attacker operates within the application's privilege boundary. UI:N: No user interaction is required. VC/VI/VA:H: Successful exploitation results in arbitrary code execution as the web user, compromising confidentiality, integrity, and availability of the MISP instance. SC/SI/SA:N: No evidence of impact on subsequent or other components beyond the MISP instance itself.
Weakness rationale
- CWE-502 The phar stream wrapper causes PHP to invoke unserialize() implicitly whenever a filesystem operation resolves to a phar archive. An attacker who can influence the path argument (e.g., via argument injection) can supply a crafted phar file, triggering deserialization of attacker-controlled data and leading to code execution. This is the primary and most specific weakness.
- CWE-74 The phar stream wrapper is a special element of the PHP runtime that was not neutralized (unregistered) in the MISP entry points. Its presence allows downstream filesystem calls to be subverted into deserialization sinks. This is a secondary, broader characterization of the same issue.
Attack pattern rationale
- CAPEC-570 The core attack mechanism is that the phar stream wrapper turns a filesystem call on a caller-influenced path into an implicit unserialize() invocation. An attacker crafts a phar archive containing a malicious serialized payload and causes the application to perform a filesystem operation on that path, triggering deserialization and code execution. CAPEC-570 is the closest match. Uncertainty: the exact injection vector (which specific MISP endpoint or console command accepts the path) is not detailed in the patch, but the deserialization sink is explicitly described in the commit message.
- CAPEC-100 The phar stream wrapper is a trusted, built-in PHP component that the attacker leverages in the MISP runtime environment where it serves no legitimate purpose. The attacker does not need to exploit a flaw in the wrapper itself; rather, its mere presence in the runtime provides the primitive. This is a secondary mapping; CAPEC-570 is preferred as the primary because it more precisely describes the deserialization mechanism.
Assumptions to verify
- The affected version range is inferred from the tag_version_boundary (v2.5.47, 42 commits after fix), suggesting the fix is included in v2.5.47 and earlier versions are affected. The explicit context lists affected_version and fixed_version as null, so the exact boundary is uncertain.
- PR:L is assumed because MISP is an authenticated threat-intelligence platform; however, the patch does not explicitly state whether the vulnerable code path requires authentication. If the argument-injection vector is reachable unauthenticated, PR should be N.
- AC:H is assumed because crafting a valid phar archive and identifying the correct code path for the filesystem call is non-trivial; the commit describes it as an 'argument-injection exploit,' implying specific conditions must be met.
- The CAPEC-570 mapping is based on the commit message's explicit description of the phar wrapper as an 'unserialize() sink'; the exact MISP endpoint or console command that accepts the attacker-influenced path is not identified in the patch.
- The commit message references 'the job-argument guard reverted,' implying a prior guard existed and was removed, making the phar wrapper the remaining defense. The exact prior guard is not described in this patch.
- The Co-Authored-By line lists 'Claude Opus 5 (1M context)' as a co-author; this is recorded in the metadata as a remediation developer but is an AI assistant, not a human contributor. It is excluded from credits to avoid attributing a CVE credit to a non-human entity.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
4 | 9 | medium | 6 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95806",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:53:57.690631Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:54:08.956Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"app/Console/cake.php",
"app/webroot/index.php"
],
"product": "MISP",
"programFiles": [
"app/Console/cake.php",
"app/webroot/index.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP ships with PHP\u0027s phar stream wrapper registered in both its web entry point and its console entry point.\u0026nbsp;\u003c/p\u003e\u003cp\u003eThe phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences:\u0026nbsp;\u2003\u003c/p\u003e\u2003-\u0026nbsp;any filesystem operation on a caller-influenced path that resolves to a phar archive triggers an implicit unserialize() call, creating a deserialization sink;\u003cbr\u003e\u003cdiv\u003e\u2003-\u0026nbsp;a relocated application root can reach executable code inside an uploaded phar file, enabling arbitrary code execution as the web user.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cp\u003eNo component of MISP, the vendored CakePHP framework, or any runtime-loaded library reads or constructs phar archives. The wrapper therefore serves no legitimate purpose in the MISP runtime and exists solely as an available primitive for an attacker who can influence a filesystem path argument.\u0026nbsp;\u003c/p\u003e"
}
],
"value": "MISP ships with PHP\u0027s phar stream wrapper registered in both its web entry point and its console entry point.\u00a0\n\nThe phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences:\u00a0\u2003\n\n\u2003-\u00a0any filesystem operation on a caller-influenced path that resolves to a phar archive triggers an implicit unserialize() call, creating a deserialization sink;\n\u2003-\u00a0a relocated application root can reach executable code inside an uploaded phar file, enabling arbitrary code execution as the web user.\n\n\n\n\nNo component of MISP, the vendored CakePHP framework, or any runtime-loaded library reads or constructs phar archives. The wrapper therefore serves no legitimate purpose in the MISP runtime and exists solely as an available primitive for an attacker who can influence a filesystem path argument."
}
],
"impacts": [
{
"capecId": "CAPEC-570",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-570 Deserialization of Untrusted Data"
}
]
},
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Leveraging Trusted Components in an Untrusted Environment"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "CWE-502 Deserialization of Untrusted Data",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:09:09.738Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/08fa755b6"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe phar stream wrapper is unregistered via stream_wrapper_unregister(\u0027phar\u0027) at the top of both the web and console entry points, before any framework bootstrap or application code executes. Because no MISP component, CakePHP, or runtime library requires the phar wrapper, removing it eliminates the implicit unserialize() sink and the directory-like phar archive behavior without functional impact. This closes the deserialization and code-execution primitive application-wide, independent of whether individual callers validate their path arguments.\u003c/p\u003e"
}
],
"value": "The phar stream wrapper is unregistered via stream_wrapper_unregister(\u0027phar\u0027) at the top of both the web and console entry points, before any framework bootstrap or application code executes. Because no MISP component, CakePHP, or runtime library requires the phar wrapper, removing it eliminates the implicit unserialize() sink and the directory-like phar archive behavior without functional impact. This closes the deserialization and code-execution primitive application-wide, independent of whether individual callers validate their path arguments."
}
],
"title": "MISP: PHP phar stream wrapper enables deserialization and code execution via caller-influenced filesystem paths",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is inferred from the tag_version_boundary (v2.5.47, 42 commits after fix), suggesting the fix is included in v2.5.47 and earlier versions are affected. The explicit context lists affected_version and fixed_version as null, so the exact boundary is uncertain.",
"PR:L is assumed because MISP is an authenticated threat-intelligence platform; however, the patch does not explicitly state whether the vulnerable code path requires authentication. If the argument-injection vector is reachable unauthenticated, PR should be N.",
"AC:H is assumed because crafting a valid phar archive and identifying the correct code path for the filesystem call is non-trivial; the commit describes it as an \u0027argument-injection exploit,\u0027 implying specific conditions must be met.",
"The CAPEC-570 mapping is based on the commit message\u0027s explicit description of the phar wrapper as an \u0027unserialize() sink\u0027; the exact MISP endpoint or console command that accepts the attacker-influenced path is not identified in the patch.",
"The commit message references \u0027the job-argument guard reverted,\u0027 implying a prior guard existed and was removed, making the phar wrapper the remaining defense. The exact prior guard is not described in this patch.",
"The Co-Authored-By line lists \u0027Claude Opus 5 (1M context)\u0027 as a co-author; this is recorded in the metadata as a remediation developer but is an AI assistant, not a human contributor. It is excluded from credits to avoid attributing a CVE credit to a non-human entity."
],
"capecRationale": [
{
"capecId": "CAPEC-570",
"rationale": "The core attack mechanism is that the phar stream wrapper turns a filesystem call on a caller-influenced path into an implicit unserialize() invocation. An attacker crafts a phar archive containing a malicious serialized payload and causes the application to perform a filesystem operation on that path, triggering deserialization and code execution. CAPEC-570 is the closest match. Uncertainty: the exact injection vector (which specific MISP endpoint or console command accepts the path) is not detailed in the patch, but the deserialization sink is explicitly described in the commit message."
},
{
"capecId": "CAPEC-100",
"rationale": "The phar stream wrapper is a trusted, built-in PHP component that the attacker leverages in the MISP runtime environment where it serves no legitimate purpose. The attacker does not need to exploit a flaw in the wrapper itself; rather, its mere presence in the runtime provides the primitive. This is a secondary mapping; CAPEC-570 is preferred as the primary because it more precisely describes the deserialization mechanism."
}
],
"commit": "08fa755b6363ec0b7194d97ea36800ae8eb8f919",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5 (1M context)"
}
],
"cvssRationale": "AV:N: The vulnerability is reachable through the web entry point (app/webroot/index.php), making it network-accessible. AC:H: Exploitation requires crafting a valid phar archive with a malicious serialized payload and identifying a code path where a caller-influenced filesystem argument resolves to that archive; the commit describes this as an \u0027argument-injection exploit,\u0027 implying non-trivial path manipulation. AT:N: No specific attack-target conditions are indicated. PR:L: MISP is a threat-intelligence platform that typically requires authenticated access; the commit references \u0027the web user\u0027 context, suggesting the attacker operates within the application\u0027s privilege boundary. UI:N: No user interaction is required. VC/VI/VA:H: Successful exploitation results in arbitrary code execution as the web user, compromising confidentiality, integrity, and availability of the MISP instance. SC/SI/SA:N: No evidence of impact on subsequent or other components beyond the MISP instance itself.",
"fixSummary": "The phar stream wrapper is unregistered via stream_wrapper_unregister(\u0027phar\u0027) at the top of both the web and console entry points, before any framework bootstrap or application code executes. Because no MISP component, CakePHP, or runtime library requires the phar wrapper, removing it eliminates the implicit unserialize() sink and the directory-like phar archive behavior without functional impact. This closes the deserialization and code-execution primitive application-wide, independent of whether individual callers validate their path arguments.",
"generatedAt": "2026-09-22T15:01:21.211955Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 6,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 4
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "f4fc3223e6421557e1c03c2182cfaa2b0c17a1a20870c71214708034faf1350f",
"patchSummary": "Two files are modified. In app/Console/cake.php and app/webroot/index.php, a 14-line block is inserted immediately after the file header comment and before any existing logic. The block checks whether \u0027phar\u0027 is present in stream_get_wrappers() and, if so, calls stream_wrapper_unregister(\u0027phar\u0027). A docblock comment explains the security rationale: the wrapper turns filesystem calls on caller-influenced paths into unserialize() sinks and allows a relocated application root to reach code inside an uploaded file. No other code is changed; the total diff is 28 insertions across the two files.",
"patchTruncated": false,
"patches": [
{
"commit": "08fa755b6363ec0b7194d97ea36800ae8eb8f919",
"patchSha256": "f4fc3223e6421557e1c03c2182cfaa2b0c17a1a20870c71214708034faf1350f",
"source": "https://github.com/MISP/MISP/commit/08fa755b6.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/08fa755b6.patch",
"subject": "chg: [internal] Unregister the phar stream wrapper in the"
}
],
"source": "https://github.com/MISP/MISP/commit/08fa755b6.patch",
"subject": "chg: [internal] Unregister the phar stream wrapper in the",
"tagVersionBoundary": {
"commits_after_fix": 42,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-502",
"rationale": "The phar stream wrapper causes PHP to invoke unserialize() implicitly whenever a filesystem operation resolves to a phar archive. An attacker who can influence the path argument (e.g., via argument injection) can supply a crafted phar file, triggering deserialization of attacker-controlled data and leading to code execution. This is the primary and most specific weakness."
},
{
"cweId": "CWE-74",
"rationale": "The phar stream wrapper is a special element of the PHP runtime that was not neutralized (unregistered) in the MISP entry points. Its presence allows downstream filesystem calls to be subverted into deserialization sinks. This is a secondary, broader characterization of the same issue."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20263"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95806",
"datePublished": "2026-09-22T15:09:09.738Z",
"dateReserved": "2026-09-22T15:09:04.977Z",
"dateUpdated": "2026-09-22T15:54:08.956Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95501 (GCVE-0-2026-95501)
Vulnerability from cvelistv5 – Published: 2026-09-22 14:30 – Updated: 2026-09-22 18:09| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408349 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408349/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-95501 | third-party-advisory |
| https://vuldb.com/submit/896603 | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95501",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T18:09:39.042492Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T18:09:46.176Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://vuldb.com/submit/896603"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:mtrano:apencms:*:*:*:*:*:*:*:*"
],
"modules": [
"Template Engine"
],
"product": "APENCMS",
"vendor": "mtrano",
"versions": [
{
"status": "affected",
"version": "6546096d354153309693efabb9a0d824628ed4f5"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "milocat (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.php of the component Template Engine. The manipulation of the argument $_CMS[\u0027site\u0027] results in code injection. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5.8,
"vectorString": "AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "Code Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:30:09.316Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408349 | mtrano APENCMS Template weasel.php eval code injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408349"
},
{
"name": "VDB-408349 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408349/cti"
},
{
"name": "CVE-2026-95501 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-95501"
},
{
"name": "Submit #896603 | mtrano (Michele Trancossi) APENCMS latest (main branch, cms/weasel.php) Code Injection / SSTI (CWE-94)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/896603"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-22T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-22T08:36:45.000Z",
"value": "VulDB entry last update"
}
],
"title": "mtrano APENCMS Template weasel.php eval code injection",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-95501",
"datePublished": "2026-09-22T14:30:09.316Z",
"dateReserved": "2026-09-22T06:31:10.568Z",
"dateUpdated": "2026-09-22T18:09:46.176Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94492 (GCVE-0-2026-94492)
Vulnerability from cvelistv5 – Published: 2026-09-22 00:30 – Updated: 2026-09-22 12:45| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408192 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408192/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-94492 | third-party-advisory |
| https://vuldb.com/submit/895368 | third-party-advisory |
| https://github.com/mjh134/--POC/blob/master/explo… | exploit |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94492",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T12:44:30.406864Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T12:45:31.289Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:yonyou:u8cloud:*:*:*:*:*:*:*:*"
],
"modules": [
"OpenAPI"
],
"product": "U8cloud",
"vendor": "Yonyou",
"versions": [
{
"status": "affected",
"version": "5.*"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "mjh_123 (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation of the argument operator leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T00:30:14.854Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408192 | Yonyou U8cloud OpenAPI so.saleorder.sendaudit sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408192"
},
{
"name": "VDB-408192 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408192/cti"
},
{
"name": "CVE-2026-94492 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-94492"
},
{
"name": "Submit #895368 | Yonyou Yonyou U8cloud (\u7528\u53cbU8cloud) 5.x SQL Injection (CWE-89)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/895368"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/mjh134/--POC/blob/master/exploits/yonyou_u8cloud_so_saleorder_sendaudit_sqli.go"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-21T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-21T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-21T19:51:58.000Z",
"value": "VulDB entry last update"
}
],
"title": "Yonyou U8cloud OpenAPI so.saleorder.sendaudit sql injection",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-94492",
"datePublished": "2026-09-22T00:30:14.854Z",
"dateReserved": "2026-09-21T17:46:48.595Z",
"dateUpdated": "2026-09-22T12:45:31.289Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
Programming languages and supporting technologies might be chosen which are not subject to these issues.
Mitigation
Utilize an appropriate mix of allowlist and denylist parsing to filter control-plane syntax from all input.
CAPEC-10: Buffer Overflow via Environment Variables
This attack pattern involves causing a buffer overflow through manipulation of environment variables. Once the adversary finds that they can modify an environment variable, they may try to overflow associated buffers. This attack leverages implicit trust often placed in environment variables.
CAPEC-101: Server Side Include (SSI) Injection
An attacker can use Server Side Include (SSI) Injection to send code to a web application that then gets executed by the web server. Doing so enables the attacker to achieve similar results to Cross Site Scripting, viz., arbitrary code execution and information disclosure, albeit on a more limited scale, since the SSI directives are nowhere near as powerful as a full-fledged scripting language. Nonetheless, the attacker can conveniently gain access to sensitive files, such as password files, and execute shell commands.
CAPEC-105: HTTP Request Splitting
An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages by different intermediary HTTP agents (e.g., load balancer, reverse proxy, web caching proxies, application firewalls, etc.) to split a single HTTP request into multiple unauthorized and malicious HTTP requests to a back-end HTTP agent (e.g., web server).
See CanPrecede relationships for possible consequences.
CAPEC-108: Command Line Execution through SQL Injection
An attacker uses standard SQL injection methods to inject data into the command line for execution. This could be done directly through misuse of directives such as MSSQL_xp_cmdshell or indirectly through injection of data into the database that would be interpreted as shell commands. Sometime later, an unscrupulous backend application (or could be part of the functionality of the same application) fetches the injected data stored in the database and uses this data as command line arguments without performing proper validation. The malicious data escapes that data plane by spawning new commands to be executed on the host.
CAPEC-120: Double Encoding
The adversary utilizes a repeating of the encoding process for a set of characters (that is, character encoding a character encoding of a character) to obfuscate the payload of a particular request. This may allow the adversary to bypass filters that attempt to detect illegal characters or strings, such as those that might be used in traversal or injection attacks. Filters may be able to catch illegal encoded strings, but may not catch doubly encoded strings. For example, a dot (.), often used in path traversal attacks and therefore often blocked by filters, could be URL encoded as %2E. However, many filters recognize this encoding and would still block the request. In a double encoding, the % in the above URL encoding would be encoded again as %25, resulting in %252E which some filters might not catch, but which could still be interpreted as a dot (.) by interpreters on the target.
CAPEC-13: Subverting Environment Variable Values
The adversary directly or indirectly modifies environment variables used by or controlling the target software. The adversary's goal is to cause the target software to deviate from its expected operation in a manner that benefits the adversary.
CAPEC-135: Format String Injection
An adversary includes formatting characters in a string input field on the target application. Most applications assume that users will provide static text and may respond unpredictably to the presence of formatting character. For example, in certain functions of the C programming languages such as printf, the formatting character %s will print the contents of a memory location expecting this location to identify a string and the formatting character %n prints the number of DWORD written in the memory. An adversary can use this to read or write to memory locations or files, or simply to manipulate the value of the resulting text in unexpected ways. Reading or writing memory may result in program crashes and writing memory could result in the execution of arbitrary code if the adversary can write to the program stack.
CAPEC-14: Client-side Injection-induced Buffer Overflow
This type of attack exploits a buffer overflow vulnerability in targeted client software through injection of malicious content from a custom-built hostile service. This hostile service is created to deliver the correct content to the client software. For example, if the client-side application is a browser, the service will host a webpage that the browser loads.
CAPEC-24: Filter Failure through Buffer Overflow
In this attack, the idea is to cause an active filter to fail by causing an oversized transaction. An attacker may try to feed overly long input strings to the program in an attempt to overwhelm the filter (by causing a buffer overflow) and hoping that the filter does not fail securely (i.e. the user input is let into the system unfiltered).
CAPEC-250: XML Injection
An attacker utilizes crafted XML user-controllable input to probe, attack, and inject data into the XML database, using techniques similar to SQL injection. The user-controllable input can allow for unauthorized viewing of data, bypassing authentication or the front-end application for direct XML database access, and possibly altering database information.
CAPEC-267: Leverage Alternate Encoding
An adversary leverages the possibility to encode potentially harmful input or content used by applications such that the applications are ineffective at validating this encoding standard.
CAPEC-273: HTTP Response Smuggling
An adversary manipulates and injects malicious content in the form of secret unauthorized HTTP responses, into a single HTTP response from a vulnerable or compromised back-end HTTP agent (e.g., server).
See CanPrecede relationships for possible consequences.
CAPEC-28: Fuzzing
In this attack pattern, the adversary leverages fuzzing to try to identify weaknesses in the system. Fuzzing is a software security and functionality testing method that feeds randomly constructed input to the system and looks for an indication that a failure in response to that input has occurred. Fuzzing treats the system as a black box and is totally free from any preconceptions or assumptions about the system. Fuzzing can help an attacker discover certain assumptions made about user input in the system. Fuzzing gives an attacker a quick way of potentially uncovering some of these assumptions despite not necessarily knowing anything about the internals of the system. These assumptions can then be turned against the system by specially crafting user input that may allow an attacker to achieve their goals.
CAPEC-3: Using Leading 'Ghost' Character Sequences to Bypass Input Filters
Some APIs will strip certain leading characters from a string of parameters. An adversary can intentionally introduce leading "ghost" characters (extra characters that don't affect the validity of the request at the API layer) that enable the input to pass the filters and therefore process the adversary's input. This occurs when the targeted API will accept input data in several syntactic forms and interpret it in the equivalent semantic way, while the filter does not take into account the full spectrum of the syntactic forms acceptable to the targeted API.
CAPEC-34: HTTP Response Splitting
An adversary manipulates and injects malicious content, in the form of secret unauthorized HTTP responses, into a single HTTP response from a vulnerable or compromised back-end HTTP agent (e.g., web server) or into an already spoofed HTTP response from an adversary controlled domain/site.
See CanPrecede relationships for possible consequences.
CAPEC-42: MIME Conversion
An attacker exploits a weakness in the MIME conversion routine to cause a buffer overflow and gain control over the mail server machine. The MIME system is designed to allow various different information formats to be interpreted and sent via e-mail. Attack points exist when data are converted to MIME compatible format and back.
CAPEC-43: Exploiting Multiple Input Interpretation Layers
An attacker supplies the target software with input data that contains sequences of special characters designed to bypass input validation logic. This exploit relies on the target making multiples passes over the input data and processing a "layer" of special characters with each pass. In this manner, the attacker can disguise input that would otherwise be rejected as invalid by concealing it with layers of special/escape characters that are stripped off by subsequent processing steps. The goal is to first discover cases where the input validation layer executes before one or more parsing layers. That is, user input may go through the following logic in an application: <parser1> --> <input validator> --> <parser2>. In such cases, the attacker will need to provide input that will pass through the input validator, but after passing through parser2, will be converted into something that the input validator was supposed to stop.
CAPEC-45: Buffer Overflow via Symbolic Links
This type of attack leverages the use of symbolic links to cause buffer overflows. An adversary can try to create or manipulate a symbolic link file such that its contents result in out of bounds data. When the target software processes the symbolic link file, it could potentially overflow internal buffers with insufficient bounds checking.
CAPEC-46: Overflow Variables and Tags
This type of attack leverages the use of tags or variables from a formatted configuration data to cause buffer overflow. The adversary crafts a malicious HTML page or configuration file that includes oversized strings, thus causing an overflow.
CAPEC-47: Buffer Overflow via Parameter Expansion
In this attack, the target software is given input that the adversary knows will be modified and expanded in size during processing. This attack relies on the target software failing to anticipate that the expanded data may exceed some internal limit, thereby creating a buffer overflow.
CAPEC-51: Poison Web Service Registry
SOA and Web Services often use a registry to perform look up, get schema information, and metadata about services. A poisoned registry can redirect (think phishing for servers) the service requester to a malicious service provider, provide incorrect information in schema or metadata, and delete information about service provider interfaces.
CAPEC-52: Embedding NULL Bytes
An adversary embeds one or more null bytes in input to the target software. This attack relies on the usage of a null-valued byte as a string terminator in many environments. The goal is for certain components of the target software to stop processing the input when it encounters the null byte(s).
CAPEC-53: Postfix, Null Terminate, and Backslash
If a string is passed through a filter of some kind, then a terminal NULL may not be valid. Using alternate representation of NULL allows an adversary to embed the NULL mid-string while postfixing the proper data so that the filter is avoided. One example is a filter that looks for a trailing slash character. If a string insertion is possible, but the slash must exist, an alternate encoding of NULL in mid-string may be used.
CAPEC-6: Argument Injection
An attacker changes the behavior or state of a targeted application through injecting data or command syntax through the targets use of non-validated and non-filtered arguments of exposed services or methods.
CAPEC-64: Using Slashes and URL Encoding Combined to Bypass Validation Logic
This attack targets the encoding of the URL combined with the encoding of the slash characters. An attacker can take advantage of the multiple ways of encoding a URL and abuse the interpretation of the URL. A URL may contain special character that need special syntax handling in order to be interpreted. Special characters are represented using a percentage character followed by two digits representing the octet code of the original character (%HEX-CODE). For instance US-ASCII space character would be represented with %20. This is often referred as escaped ending or percent-encoding. Since the server decodes the URL from the requests, it may restrict the access to some URL paths by validating and filtering out the URL requests it received. An attacker will try to craft an URL with a sequence of special characters which once interpreted by the server will be equivalent to a forbidden URL. It can be difficult to protect against this attack since the URL can contain other format of encoding such as UTF-8 encoding, Unicode-encoding, etc.
CAPEC-67: String Format Overflow in syslog()
This attack targets applications and software that uses the syslog() function insecurely. If an application does not explicitely use a format string parameter in a call to syslog(), user input can be placed in the format string parameter leading to a format string injection attack. Adversaries can then inject malicious format string commands into the function call leading to a buffer overflow. There are many reported software vulnerabilities with the root cause being a misuse of the syslog() function.
CAPEC-7: Blind SQL Injection
Blind SQL Injection results from an insufficient mitigation for SQL Injection. Although suppressing database error messages are considered best practice, the suppression alone is not sufficient to prevent SQL Injection. Blind SQL Injection is a form of SQL Injection that overcomes the lack of error messages. Without the error messages that facilitate SQL Injection, the adversary constructs input strings that probe the target through simple Boolean SQL expressions. The adversary can determine if the syntax and structure of the injection was successful based on whether the query was executed or not. Applied iteratively, the adversary determines how and where the target is vulnerable to SQL Injection.
CAPEC-71: Using Unicode Encoding to Bypass Validation Logic
An attacker may provide a Unicode string to a system component that is not Unicode aware and use that to circumvent the filter or cause the classifying mechanism to fail to properly understanding the request. That may allow the attacker to slip malicious data past the content filter and/or possibly cause the application to route the request incorrectly.
CAPEC-72: URL Encoding
This attack targets the encoding of the URL. An adversary can take advantage of the multiple way of encoding an URL and abuse the interpretation of the URL.
CAPEC-76: Manipulating Web Input to File System Calls
An attacker manipulates inputs to the target software which the target software passes to file system calls in the OS. The goal is to gain access to, and perhaps modify, areas of the file system that the target software did not intend to be accessible.
CAPEC-78: Using Escaped Slashes in Alternate Encoding
This attack targets the use of the backslash in alternate encoding. An adversary can provide a backslash as a leading character and causes a parser to believe that the next character is special. This is called an escape. By using that trick, the adversary tries to exploit alternate ways to encode the same character which leads to filter problems and opens avenues to attack.
CAPEC-79: Using Slashes in Alternate Encoding
This attack targets the encoding of the Slash characters. An adversary would try to exploit common filtering problems related to the use of the slashes characters to gain access to resources on the target host. Directory-driven systems, such as file systems and databases, typically use the slash character to indicate traversal between directories or other container components. For murky historical reasons, PCs (and, as a result, Microsoft OSs) choose to use a backslash, whereas the UNIX world typically makes use of the forward slash. The schizophrenic result is that many MS-based systems are required to understand both forms of the slash. This gives the adversary many opportunities to discover and abuse a number of common filtering problems. The goal of this pattern is to discover server software that only applies filters to one version, but not the other.
CAPEC-8: Buffer Overflow in an API Call
This attack targets libraries or shared code modules which are vulnerable to buffer overflow attacks. An adversary who has knowledge of known vulnerable libraries or shared code can easily target software that makes use of these libraries. All clients that make use of the code library thus become vulnerable by association. This has a very broad effect on security across a system, usually affecting more than one software process.
CAPEC-80: Using UTF-8 Encoding to Bypass Validation Logic
This attack is a specific variation on leveraging alternate encodings to bypass validation logic. This attack leverages the possibility to encode potentially harmful input in UTF-8 and submit it to applications not expecting or effective at validating this encoding standard making input filtering difficult. UTF-8 (8-bit UCS/Unicode Transformation Format) is a variable-length character encoding for Unicode. Legal UTF-8 characters are one to four bytes long. However, early version of the UTF-8 specification got some entries wrong (in some cases it permitted overlong characters). UTF-8 encoders are supposed to use the "shortest possible" encoding, but naive decoders may accept encodings that are longer than necessary. According to the RFC 3629, a particularly subtle form of this attack can be carried out against a parser which performs security-critical validity checks against the UTF-8 encoded form of its input, but interprets certain illegal octet sequences as characters.
CAPEC-83: XPath Injection
An attacker can craft special user-controllable input consisting of XPath expressions to inject the XML database and bypass authentication or glean information that they normally would not be able to. XPath Injection enables an attacker to talk directly to the XML database, thus bypassing the application completely. XPath Injection results from the failure of an application to properly sanitize input used as part of dynamic XPath expressions used to query an XML database.
CAPEC-84: XQuery Injection
This attack utilizes XQuery to probe and attack server systems; in a similar manner that SQL Injection allows an attacker to exploit SQL calls to RDBMS, XQuery Injection uses improperly validated data that is passed to XQuery commands to traverse and execute commands that the XQuery routines have access to. XQuery injection can be used to enumerate elements on the victim's environment, inject commands to the local host, or execute queries to remote files and data sources.
CAPEC-9: Buffer Overflow in Local Command-Line Utilities
This attack targets command-line utilities available in a number of shells. An adversary can leverage a vulnerability found in a command-line utility to escalate privilege to root.