CVE-2026-27179 is an unauthenticated SQL injection vulnerability in MajorDoMo (Major Domestic Module), specifically within the commands module. This critical vulnerability (CVSS 9.8) allows an attacker to inject malicious SQL queries due to improper sanitization of the $_GET['parent'] parameter in commands_search.inc.php, accessible without authentication. Successful exploitation enables time-based blind SQL injection to extract unsalted MD5 admin password hashes, leading to full administrative panel access and complete compromise of the system. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, including mentions of a fix addressing this and other security issues.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:mjdm:majordomo:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.