PT-2026-34664 · Unknown · Socialengine
Egidio Romano
·
Published
2026-04-23
·
Updated
2026-04-27
·
CVE-2026-41460
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SocialEngine versions 7.8.0 and prior
Description
An issue exists in the '/activity/index/get-memberall' endpoint where user-supplied input passed via the
text parameter is not sanitized before being incorporated into a SQL query. This allows an unauthenticated remote attacker to read arbitrary data from the database, reset administrator account passwords, and gain unauthorized access to the Packages Manager in the Admin Panel, which could potentially enable remote code execution.Recommendations
Update SocialEngine to a version later than 7.8.0.
Avoid using the
text parameter in the '/activity/index/get-memberall' endpoint until the issue is resolved.Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Socialengine