PT-2026-97513 · Unknown · Easy Store

CVE-2026-90901

·

Published

2026-09-23

·

Updated

2026-09-25

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Easy Store versions 1.0.0 through 3.0.0
Description Two distinct issues exist in the extension. First, the endpoint 'administrator/index.php?option=com easystore&task=media.deleteImage' fails to properly sanitize the ids parameter, which is processed as a comma-separated string and inserted directly into SQL IN clauses within Media.php and MediaModel.php. This allows an authenticated administrator or an attacker with admin session access to execute arbitrary SQL statements. Second, the 'checkout.searchGuestUser' endpoint allows the retrieval of complete shipping details—including full name, phone number, street address, city, postal code, and country—from the # easystore guests table by providing an email address. This occurs without authentication or session validation, enabling unauthenticated attackers to harvest Personally Identifiable Information (PII) through email enumeration.
Recommendations Update Easy Store to a version where the unauthenticated server-side guest lookup endpoint is removed and the media deletion logic is patched to prevent SQL injection.

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90901

Affected Products

Easy Store