Impact
A vulnerability in highwarden Super Store Finder allows attackers to manipulate the latitude and longitude parameters in the file /products/superstorefinder/index.php. This manipulation leads to an unsanitized SQL query that can be exploited for SQL injection, potentially exposing or altering sensitive data. The description states that the vulnerability is remotely exploitable, meaning an attacker does not need local access to influence the application.
Affected Systems
Affected systems are the highwarden Super Store Finder product for versions up to 3.8. The vendor has supplied a fix in version 3.9, which addresses the injection flaw.
Risk and Exploitability
Risk and exploitability assessment shows a CVSS score of 5.3, indicating moderate severity. No EPSS score is available, and the issue is not listed in KEV. The attack vector is inferred to be remote via HTTP requests containing the lat/lng parameters, and no authentication appears to be required. Once exploited, an attacker could execute arbitrary SQL statements against the backend database, leading to data compromise or corruption.
OpenCVE Enrichment