PT-2026-97514 · Unknown · Easy Store
CVE-2026-90902
·
Published
2026-09-23
·
Updated
2026-09-25
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Easy Store versions 1.0.0 through 3.0.0
Description
An authenticated administrator can perform a SQL Injection through the coupon bulk update task. The issue occurs because the application takes input IDs and directly concatenates them into raw SQL IN clauses within
ProductCoupon.php and CouponsModel.php without proper sanitization or parameterization. This allows a privileged user to manipulate database queries via the endpoint 'administrator/index.php?option=com easystore&task=coupon.couponBulkUpdate'.Recommendations
Update Easy Store to a version where IDs are strictly cast to integers and parameterized
->whereIn() query construction is used for versions 1.0.0 through 3.0.0.Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easy Store