惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
Recent Announcements
Recent Announcements
V
Visual Studio Blog
博客园 - 叶小钗
H
Help Net Security
aimingoo的专栏
aimingoo的专栏
宝玉的分享
宝玉的分享
U
Unit 42
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
V
V2EX
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
D
DataBreaches.Net
J
Java Code Geeks
H
Hackread – Cybersecurity News, Data Breaches, AI and More
A
About on SuperTechFans
酷 壳 – CoolShell
酷 壳 – CoolShell
量子位
C
Check Point Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
Microsoft Azure Blog
Microsoft Azure Blog
M
MIT News - Artificial intelligence

Full Disclosure

Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver [NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure Full Disclosure: Subject: Advisory Submission: EZ Game Booster Full Disclosure: CVE-2026-56877 - Skillable SCORM userId authorisation bypass Full Disclosure: [REVIVE-SA-2026-003] Revive Adserver Vulnerabilities Full Disclosure: OPNsense XPATH Injection (CVE-2026-53582) Authentication Bypass for SafeLine SL6 and SL6+ confidentiality and anonymity leakage to third parties Full Disclosure: OpenBlow Multiple Deanonymization Vulnerabilities Site-access password exposed in web server access logs via GET query string Full Disclosure: APPLE-SA-06-29-2026-3 Safari 26.5.2 Full Disclosure: APPLE-SA-06-29-2026-2 macOS Tahoe 26.5.2 APPLE-SA-06-29-2026-1 iOS 26.5.2 and iPadOS 26.5.2 symlink following and TOCTOU in privileged upload handler allow arbitrary file write as root [KIS-2026-12] Control Web Panel <= 0.9.8.1224 (userRes) SQL Injection Vulnerability Full Disclosure: [fulldis] CVE-2026-58451 - Horde Groupware IMP path traversal vuln Full Disclosure: Samsung Galaxy Buds – Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption (Vendor Response: Working as Intended) Full Disclosure: Asterisk Security Release 23.4.1 Full Disclosure: Asterisk Security Release 22.10.1 Full Disclosure: Asterisk Security Release 21.12.3 Full Disclosure: Asterisk Security Release 20.20.1 Certified Asterisk Security Release certified-22.8-cert3 Certified Asterisk Security Release certified-20.7-cert11 Zig std.http chunked reader integer overflow -> unauthenticated remote DoS Remote Kernel Stack Disclosure via MPLS Label Stack Over-read Full Disclosure: OpenBSD sppp_pap_input: PAP authentication bypass Full Disclosure: SEC Consult SA-20260618-0 :: Hardcoded Root Cloud Credentials in Application Binaries in Silver Leaf Technologies Full Disclosure: SEC Consult SA-20260617-1 :: Multiple Vulnerabilities in Quanos Content Solutions Multiple Critical Vulnerabilities in Sprecher Automation SPRECON-E-C/-E-P/-E-T3 Full Disclosure: SEC Consult SA-20260616-0 :: Broken Access Control in syracom AG Secure Login (2FA) for Atlassian Jira / Confluence
[KIS-2026-08] SocialEngine <= 7.8.0 (get-memberall) SQL I...
2026-04-30 · via Full Disclosure
fulldisclosure logo

Full Disclosure mailing list archives


From: Egidio Romano <n0b0d13s () gmail com>
Date: Thu, 23 Apr 2026 11:15:04 +0200

-----------------------------------------------------------------
SocialEngine <= 7.8.0 (get-memberall) SQL Injection Vulnerability
-----------------------------------------------------------------


[-] Software Link:

https://socialengine.com


[-] Affected Versions:

Versions 7.8.0, 7.7.0, and likely prior versions.


[-] Vulnerability Description:

User input passed through the "text" request parameter to the
/activity/index/get-memberall endpoint is not properly sanitized
before being used to construct an SQL query. This can be exploited by
remote, unauthenticated attackers to read arbitrary, sensitive data
from the underlying database through in-band SQL Injection attacks.

NOTE: this might also be exploited to reset admin users' passwords and
gain unauthorized access to the "Packages Manager" in the Admin Panel,
in order to achieve Remote Code Execution (RCE).


[-] Proof of Concept:

https://karmainsecurity.com/pocs/CVE-2026-41460.php


[-] Solution:

No official solution is currently available.


[-] Disclosure Timeline:

[02/02/2026] - Vulnerability confirmed on version 7.7.0

[02/02/2026] - Vendor notified

[09/02/2026] - Vendor response stating "We are currently validating
your report... If this issue is confirmed, we will prioritize
appropriate fixes and include them in an upcoming update."

[27/02/2026] - Vendor released version 7.8.0, but the vulnerability is
still not fixed

[02/03/2026] - Vendor contacted again

[09/03/2026] - Vendor response stating "We will check and update you."

[23/03/2026] - Vendor notified about 60-day disclosure deadline policy

[25/03/2026] - Vendor said this issue has been fixed on the demo
website, and invited me to test it

[25/03/2026] - Vendor was informed the demo website looks not vulnerable anymore

[03/04/2026] - Reached 60-day disclosure deadline, still no official solution

[21/04/2026] - CVE identifier requested

[22/04/2026] - CVE identifier assigned

[23/04/2026] - Public disclosure


[-] CVE Reference:

CVE-2026-41460 has been assigned to this vulnerability.


[-] Credits:

Vulnerability discovered by Egidio Romano.


[-] Original Advisory:

https://karmainsecurity.com/KIS-2026-08
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread:

  • [KIS-2026-08] SocialEngine <= 7.8.0 (get-memberall) SQL Injection Vulnerability Egidio Romano (Apr 29)