在 Feng Office(风办公)3.11.13.11 及更早版本中发现了一个漏洞。受影响的是组件“Reorder Handlers”中 文件里的 / 函数。对参数 / 进行操作可导致 SQL 注入。该攻击可由远程发起。该漏洞的利用方式已公开,可能已被使用。厂商曾就此披露事宜被提前联系,但未做出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fengoffice | Feng Office | 3.11.13.0 |
cpe:2.3:a:fengoffice:feng_office:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90495 | 7.3 HIGH | Fengoffice Feng Office Legacy API CompanyWebsite.class.php instance->findAll sql injection |
| CVE-2026-90497 | 3.5 LOW | Fengoffice Feng Office Task Title Output add_task.php getTitle cross site scripting |
No comments yet