{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/moosocial--3.2.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:moosocial:moosocial:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105149"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mooSocial (\u003c= 3.2.4)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sqli","remote-execution"],"_cs_type":"threat","_cs_vendors":["mooSocial"],"content_html":"\u003cp\u003eA SQL injection vulnerability has been identified in mooSocial versions up to 3.2.4, which allows remote, unauthenticated attackers to execute arbitrary SQL commands against the underlying database. The vulnerability exists within the processing logic of the /stores/all-products endpoint, specifically involving the 'rating' argument. An exploit for this vulnerability has been publicly released, increasing the risk of active exploitation. The vendor has not responded to vulnerability disclosure attempts, leaving affected deployments without an official patch or guidance from the manufacturer. Defenders should assume that public exploit scripts are being utilized in opportunistic scans targeting these endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to unauthorized database access, which may result in data exfiltration, modification, or complete database compromise. As the software is commonly used for social networking sites, potential impact includes the theft of user credentials, personal information, and session data. Given the availability of public exploits, all internet-facing instances of mooSocial 3.2.4 or earlier are at immediate risk of compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should monitor web access logs for suspicious patterns directed at the identified endpoint.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement monitoring for HTTP requests containing SQL injection payloads targeting the /stores/all-products endpoint.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to inspect and block inputs to the 'rating' parameter that contain SQL keywords or special characters.\u003c/li\u003e\n\u003cli\u003eDue to the lack of an official patch, isolate affected mooSocial instances from the public internet if possible until security controls are verified.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-04T14:52:51Z","date_published":"2026-10-04T14:52:51Z","id":"https://feed.craftedsignal.io/briefs/2026-10-moosocial-sqli/","summary":"mooSocial versions up to 3.2.4 are vulnerable to remote SQL injection via the rating argument in the /stores/all-products endpoint, with public exploit code currently available.","title":"SQL Injection in mooSocial via Product Rating","url":"https://feed.craftedsignal.io/briefs/2026-10-moosocial-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - MooSocial (\u003c= 3.2.4)","version":"https://jsonfeed.org/version/1.1"}