SQL Injection in mooSocial via Product Rating
mooSocial versions up to 3.2.4 are vulnerable to remote SQL injection via the rating argument in the /stores/all-products endpoint, with public exploit code currently available.
CVE search metadata
CVE search record: CVE-2026-105149. Severity: high. CVSS: 7.3. KEV: no. Product: mooSocial (<= 3.2.4). Brief: SQL Injection in mooSocial via Product Rating. Brief link: https://feed.craftedsignal.io/briefs/2026-10-moosocial-sqli/
A SQL injection vulnerability has been identified in mooSocial versions up to 3.2.4, which allows remote, unauthenticated attackers to execute arbitrary SQL commands against the underlying database. The vulnerability exists within the processing logic of the /stores/all-products endpoint, specifically involving the 'rating' argument. An exploit for this vulnerability has been publicly released, increasing the risk of active exploitation. The vendor has not responded to vulnerability disclosure attempts, leaving affected deployments without an official patch or guidance from the manufacturer. Defenders should assume that public exploit scripts are being utilized in opportunistic scans targeting these endpoints.
Impact
Successful exploitation of this vulnerability leads to unauthorized database access, which may result in data exfiltration, modification, or complete database compromise. As the software is commonly used for social networking sites, potential impact includes the theft of user credentials, personal information, and session data. Given the availability of public exploits, all internet-facing instances of mooSocial 3.2.4 or earlier are at immediate risk of compromise.
Recommendation
Detection engineering teams should monitor web access logs for suspicious patterns directed at the identified endpoint.
- Implement monitoring for HTTP requests containing SQL injection payloads targeting the /stores/all-products endpoint.
- Deploy web application firewall (WAF) rules to inspect and block inputs to the 'rating' parameter that contain SQL keywords or special characters.
- Due to the lack of an official patch, isolate affected mooSocial instances from the public internet if possible until security controls are verified.
Immediate actions
Review web access logs for requests to /stores/all-products containing SQL metacharacters
Mitigations
Restrict access to /stores/all-products via WAF or web server configuration
CVE-2026-105149
Detection coverage 1
Detects CVE-2026-105149 Exploitation - SQL Injection in mooSocial
highDetects exploitation of CVE-2026-105149 by identifying SQL injection payloads in the rating parameter of the /stores/all-products endpoint.
Detection queries are available on the platform. Get full rules →