{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/readyecommerce--4.5.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-63106"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ReadyEcommerce (\u003c 4.5.2)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ReadyEcommerce"],"content_html":"\u003cp\u003eReadyEcommerce versions prior to 4.5.2 contain a critical unauthenticated SQL injection vulnerability in the product listing API. The vulnerability originates in \u003ccode\u003eProductController.php\u003c/code\u003e, where the \u003ccode\u003erating\u003c/code\u003e parameter is concatenated directly into a MySQL \u003ccode\u003eHAVING\u003c/code\u003e clause without proper parameterization. This flaw allows unauthenticated remote attackers to execute arbitrary SQL queries against the underlying database via time-based blind SQL injection techniques. Given the reported configuration where the database service runs with root privileges, successful exploitation may lead to full database compromise, extraction of sensitive user credentials and administrator password hashes, and potential file system access. This vulnerability poses a severe risk to the confidentiality and integrity of the affected e-commerce environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the full extraction of database contents, including user credentials and administrative password hashes. Due to the database running with root privileges, there is a risk of escalation to unauthorized file system access on the host server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate ReadyEcommerce to version 4.5.2 or later to remediate the vulnerability in \u003ccode\u003eProductController.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eImplement input validation and parameterized queries to prevent SQL injection in the product listing API.\u003c/li\u003e\n\u003cli\u003eAudit database service configurations to ensure that the database process runs with the least privilege necessary rather than root.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eGET\u003c/code\u003e requests to the product listing endpoint containing SQL syntax or time-delay functions (e.g., \u003ccode\u003eSLEEP()\u003c/code\u003e, \u003ccode\u003eBENCHMARK()\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T15:31:27Z","date_published":"2026-08-10T15:31:27Z","id":"https://feed.craftedsignal.io/briefs/2026-08-readyecommerce-sql-injection/","summary":"ReadyEcommerce versions before 4.5.2 are vulnerable to unauthenticated time-based blind SQL injection in the product listing API, allowing attackers to exfiltrate database contents and potentially gain system-level access.","title":"Unauthenticated SQL Injection in ReadyEcommerce Product API","url":"https://feed.craftedsignal.io/briefs/2026-08-readyecommerce-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - ReadyEcommerce (\u003c 4.5.2)","version":"https://jsonfeed.org/version/1.1"}