Executive brief
Feng Office is a web-based collaboration and document management platform. A SQL injection vulnerability in the Legacy API's contact search function allows remote attackers to manipulate database queries, potentially exposing sensitive company contact data, employee information, or enabling unauthorized data modification or deletion.
Technical details
A SQL injection vulnerability exists in the Contacts::instance->findAll function of the CompanyWebsite.class.php file in Feng Office's Legacy API. The vulnerability stems from insufficient input validation on the auth parameter, allowing attackers to inject arbitrary SQL commands. The attack requires network access to the Feng Office instance and can be executed remotely without authentication. An attacker can extract sensitive data from the database, modify existing records, or potentially escalate privileges depending on database permissions. A public proof-of-concept has been disclosed.
Affected products
- Fengoffice Feng Office up to 3.11.13.11
Timeline
- 2026-09-13: disclosed
- 2026-09-13: advisory