Impact
Ready eCommerce versions prior to 4.5.2 contain a vulnerable product listing API that accepts an unsanitized rating parameter. The value of this parameter is concatenated into a MySQL HAVING clause without proper parameterization, allowing attackers to perform time‑based blind SQL injection. Successful exploitation can extract the entire database, including user credentials, administrator password hashes, and with the database connection running as root, may enable further file system access.
Affected Systems
This flaw affects Razinsoft’s Ready eCommerce product, specifically all releases before version 4.5.2. These versions are likely to be in use on public or semi‑public ecommerce sites that expose the product listing endpoint without authentication.
Risk and Exploitability
The vulnerability is rated CVSS 9.3, indicating a severe security impact. Although EPSS is not available, the unauthenticated nature of the attack vector suggests a high likelihood of exploitation if the API is publicly accessible. The flaw is not listed in the CISA KEV catalog, but the combination of blind SQL injection and root‑level database access presents a significant risk of data exfiltration and possible pivot to system compromise.
OpenCVE Enrichment