Impact
An error-based SQL injection vulnerability was found in the CustomerTransformerController of CoreShop’s admin interface. Unsanitized user input is interpolated into a database query, causing database error disclosure and the potential extraction of sensitive data. The weakness is classified as CWE‑564 and exposes confidentiality of customer data when exploited.
Affected Systems
Vendors affected are CoreShop. The issue exists in all CoreShop releases prior to version 4.1.9. Upgrading to 4.1.9 or later eliminates the flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating a medium severity. The EPSS score is less than 1 %, meaning the likelihood of exploitation at the time of this analysis is low, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is an authenticated administrator using the customer-company-modifier endpoint; the explanation is inferred from the description and typical usage of admin panels.
OpenCVE Enrichment
Github GHSA