PT-2026-97513 · Unknown · Easy Store
CVE-2026-90901
·
Published
2026-09-23
·
Updated
2026-09-25
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Easy Store versions 1.0.0 through 3.0.0
Description
Two distinct issues exist in the extension. First, the endpoint 'administrator/index.php?option=com easystore&task=media.deleteImage' fails to properly sanitize the
ids parameter, which is processed as a comma-separated string and inserted directly into SQL IN clauses within Media.php and MediaModel.php. This allows an authenticated administrator or an attacker with admin session access to execute arbitrary SQL statements. Second, the 'checkout.searchGuestUser' endpoint allows the retrieval of complete shipping details—including full name, phone number, street address, city, postal code, and country—from the # easystore guests table by providing an email address. This occurs without authentication or session validation, enabling unauthenticated attackers to harvest Personally Identifiable Information (PII) through email enumeration.Recommendations
Update Easy Store to a version where the unauthenticated server-side guest lookup endpoint is removed and the media deletion logic is patched to prevent SQL injection.
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easy Store