---
id: CVE-2026-105146
title: >-
  A vulnerability was found in Comsenz Discuz!
  X5.0-20260801/X5.0-20260820/X5.0-20260910
summary: >-
  A vulnerability was found in Comsenz Discuz!
  X5.0-20260801/X5.0-20260820/X5.0-20260910. Affected by this issue is the
  function modmedalsubmit of the file
  upload/source/app/admin/child/medals/mod.php of the component Admin Medal
  Moderatio…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: Comsenz
product: Discuz!
affected:
  - Discuz! X5.0-20260801
  - Discuz! X5.0-20260820
  - Discuz! X5.0-20260910
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T11:16:32.857'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105146'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-105146'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/945923'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413371'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413371/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T10:57:52.586Z'
---

## Overview

A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. Affected by this issue is the function modmedalsubmit of the file upload/source/app/admin/child/medals/mod.php of the component Admin Medal Moderation. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
