CyberRota Analysis
AI-GeneratedA SQL Injection vulnerability exists in Woltlab WCF versions 6.2.4 and earlier, enabling remote attackers to manipulate user options through the `updateUserOptions` function in `UserEditor.class.php` and the `update` action in `UserAction.class.php`. This flaw could lead to unauthorized data modification or access, posing a significant risk to user data integrity. Organizations using affected versions should prioritize remediation to safeguard against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php