high · CVSS v3 7.3 · CVSS v4 6.9 · EPSS 0.00254
CVE-2026-96602
CVE-2026-96602 is a high‑severity SQL injection flaw in the customerSignin.php file of Abdurrab5’s online‑makeup‑store. The vulnerability al
Overview
CVE-2026-96602 is a high‑severity SQL injection flaw in the customerSignin.php file of Abdurrab5’s online‑makeup‑store. The vulnerability allows remote attackers to inject arbitrary SQL through the username or password fields during login, potentially exposing or altering customer data.
Description
A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure.
Impact
The flaw compromises confidentiality by allowing attackers to read or modify customer data, integrity by enabling unauthorized changes to the database, and availability if the database is disrupted. Defenders should treat affected instances as compromised until patched. The vulnerability is exploitable remotely without authentication, so all publicly accessible deployments are at risk.
Remediation
Apply the vendor’s latest patch or update to the latest rolling release that addresses the SQL injection in customerSignin.php. If a patch is not yet available, mitigate by implementing input validation or parameterized queries for the login form, or by placing the login endpoint behind a Web Application Firewall that blocks suspicious SQL patterns. Monitor logs for failed login attempts and anomalous database queries.
Risk context
With a CVSS v3 score of 7.3 and an EPSS of 0.00254, the risk is moderate but the vulnerability is publicly exploitable. Immediate attention is recommended, especially for publicly exposed installations.
Affected products
- Abdurrab5 online-makeup-store
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.3
- CVSS v4
- 6.9
- EPSS
- 0.00254