<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:moosocial:moosocial:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amoosocialmoosocial/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 04 Oct 2026 14:52:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amoosocialmoosocial/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection in mooSocial via Product Rating</title><link>https://feed.craftedsignal.io/briefs/2026-10-moosocial-sqli/</link><pubDate>Sun, 04 Oct 2026 14:52:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-moosocial-sqli/</guid><description>mooSocial versions up to 3.2.4 are vulnerable to remote SQL injection via the rating argument in the /stores/all-products endpoint, with public exploit code currently available.</description><content:encoded><![CDATA[<p>A SQL injection vulnerability has been identified in mooSocial versions up to 3.2.4, which allows remote, unauthenticated attackers to execute arbitrary SQL commands against the underlying database. The vulnerability exists within the processing logic of the /stores/all-products endpoint, specifically involving the 'rating' argument. An exploit for this vulnerability has been publicly released, increasing the risk of active exploitation. The vendor has not responded to vulnerability disclosure attempts, leaving affected deployments without an official patch or guidance from the manufacturer. Defenders should assume that public exploit scripts are being utilized in opportunistic scans targeting these endpoints.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability leads to unauthorized database access, which may result in data exfiltration, modification, or complete database compromise. As the software is commonly used for social networking sites, potential impact includes the theft of user credentials, personal information, and session data. Given the availability of public exploits, all internet-facing instances of mooSocial 3.2.4 or earlier are at immediate risk of compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection engineering teams should monitor web access logs for suspicious patterns directed at the identified endpoint.</p>
<ul>
<li>Implement monitoring for HTTP requests containing SQL injection payloads targeting the /stores/all-products endpoint.</li>
<li>Deploy web application firewall (WAF) rules to inspect and block inputs to the 'rating' parameter that contain SQL keywords or special characters.</li>
<li>Due to the lack of an official patch, isolate affected mooSocial instances from the public internet if possible until security controls are verified.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>web-vulnerability</category><category>sqli</category><category>remote-execution</category></item></channel></rss>