A SQL Injection vulnerability exists in Woltlab WCF versions 6.2.4 and earlier. This issue allows a remote attacker to update user options via UserEditor.class.php and the update action in UserAction.class.php. Defenders should assess exposure, particularly those managing user accounts or systems using Woltlab WCF. The vulnerability's impact on confidentiality, integrity, or availability requires verifica [truncated]
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code. This vulnerability allows for potential code execution, impacting the securi [truncated]