Description
A vulnerability has been found in highwarden Super Store Finder up to 3.8. Affected is an unknown function of the file /products/superstorefinder/index.php. The manipulation of the argument lat/lng leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 3.9 is able to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in highwarden Super Store Finder allows attackers to manipulate the latitude and longitude parameters in the file /products/superstorefinder/index.php. This manipulation leads to an unsanitized SQL query that can be exploited for SQL injection, potentially exposing or altering sensitive data. The description states that the vulnerability is remotely exploitable, meaning an attacker does not need local access to influence the application.

Affected Systems

Affected systems are the highwarden Super Store Finder product for versions up to 3.8. The vendor has supplied a fix in version 3.9, which addresses the injection flaw.

Risk and Exploitability

Risk and exploitability assessment shows a CVSS score of 5.3, indicating moderate severity. No EPSS score is available, and the issue is not listed in KEV. The attack vector is inferred to be remote via HTTP requests containing the lat/lng parameters, and no authentication appears to be required. Once exploited, an attacker could execute arbitrary SQL statements against the backend database, leading to data compromise or corruption.

Generated by OpenCVE AI on October 11, 2026 at 08:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Super Store Finder to version 3.9 or later to remove the vulnerable code.
  • Apply input validation or sanitization on the latitude and longitude parameters to prevent SQL injection.
  • If an upgrade cannot be performed immediately, restrict direct access to /products/superstorefinder/index.php or disable the vulnerable functionality until a patch is applied.

Generated by OpenCVE AI on October 11, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in highwarden Super Store Finder up to 3.8. Affected is an unknown function of the file /products/superstorefinder/index.php. The manipulation of the argument lat/lng leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 3.9 is able to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title highwarden Super Store Finder index.php sql injection
First Time appeared Highwarden
Highwarden super Store Finder
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:highwarden:super_store_finder:*:*:*:*:*:*:*:*
Vendors & Products Highwarden
Highwarden super Store Finder
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Highwarden Super Store Finder
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-11T06:30:14.152Z

Reserved: 2026-10-10T13:28:55.151Z

Link: CVE-2026-108541

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:23.700

Modified: 2026-10-11T07:17:23.700

Link: CVE-2026-108541

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T09:00:14Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')