Impact
A flaw has been identified in CodeAstro Ecommerce Website 1.0 that allows a remote attacker to manipulate the delete_wishlist parameter in the /customer/my_account.php?my_wishlist endpoint, resulting in arbitrary SQL injection. This vulnerability can enable the execution of unauthorized database queries, allowing the attacker to read, modify, or delete stored data and therefore compromising the confidentiality and integrity of the application’s database. The weakness is classified as CWE-74 and CWE-89 and has a publicly released exploit that demonstrates the attack can be carried out remotely.
Affected Systems
The affected product is CodeAstro Ecommerce Website version 1.0, accessed via the /customer/my_account.php?my_wishlist page. The vulnerability is triggered by the delete_wishlist argument, but no other versions or products are mentioned in the CVE data.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity level for potential data compromise. The EPSS score of < 1% suggests a very low probability of exploitation under typical circumstances, and the vulnerability is not listed in the CISA KEV catalog. Despite these low exploitation likelihood metrics, a publicly available exploit and the ability to launch the attack remotely raise operational concern, especially for sites that rely on the vulnerable component for customer account management.
OpenCVE Enrichment