EIP-2026-109535

PRE-CVE

MOD Guthabenhack 1.3 For Woltlab Burning Board - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109535. PoCs published by [email protected].

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in MOD Guthabenhack for Woltlab Burning Board, allowing an attacker to bypass authentication by manipulating the 'geworbenv' form field. The provided JavaScript snippet injects a payload to alter the 'groupid' parameter, potentially elevating privileges.

Description

MOD Guthabenhack 1.3 For Woltlab Burning Board - SQL Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/22977

This exploit demonstrates an SQL injection vulnerability in MOD Guthabenhack for Woltlab Burning Board, allowing an attacker to bypass authentication by manipulating the 'geworbenv' form field. The provided JavaScript snippet injects a payload to alter the 'groupid' parameter, potentially elevating privileges.

Classification
Working Poc 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: MOD Guthabenhack for Woltlab Burning Board
No auth needed
Prerequisites: Access to a vulnerable Woltlab Burning Board instance with MOD Guthabenhack installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026