CVE-2026-105146 | Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910 Admin Medal Moderation mod.php modmedalsubmit delete sql injection

SecurityVulns

A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. It has been declared as critical. Affected by this issue is the function modmedalsubmit of the file upload/source/app/admin/child/medals/mod.php of the component Admin Medal Moderation. The manipulation of the argument delete results in sql injection.

This vulnerability is known as CVE-2026-105146. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More