Description
A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-08
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL injection that can expose or alter database contents
Action: Apply Patch
AI Analysis

Impact

The flaw allows an attacker to inject arbitrary SQL through the Search argument of the member_list function in controllers/member.php. By crafting malicious input, an adversary can execute unintended SQL statements against the underlying database, potentially reading sensitive data, modifying records, or deleting information. This results in data confidentiality, integrity, and availability compromise.

Affected Systems

aircheng-org iWebShop-5 versions up to 5.15 are affected. Any deployment of this open‑source e‑commerce platform that has not applied a patch and still exposes the member_list endpoint is vulnerable.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderately serious weakness. Although the EPSS score is not available, the vulnerability is publicly known and an exploit has been released, meaning remote actors can readily target it. It is not listed in CISA’s KEV catalog, so it is considered a general‑purpose issue rather than a known actively exploited exploit. Attackers only need to send a crafted request to the Search parameter, requiring no special privileges on the web server or database. In the absence of an official patch, the risk remains moderate to high for unmitigated instances.

Generated by OpenCVE AI on September 8, 2026 at 18:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for iWebShop-5 as soon as it becomes available.
  • If a patch is not yet released, restrict or remove access to the Search parameter in the member_list endpoint via a Web Application Firewall or by editing the application code to reject unexpected input.
  • Introduce strict input validation and proper escaping for all parameters accepted by member_list, ensuring that any remaining SQL queries use parameterized statements.

Generated by OpenCVE AI on September 8, 2026 at 18:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title aircheng-org iWebShop-5 member.php member_list sql injection
First Time appeared Aircheng-org
Aircheng-org iwebshop-5
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:aircheng-org:iwebshop-5:*:*:*:*:*:*:*:*
Vendors & Products Aircheng-org
Aircheng-org iwebshop-5
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Aircheng-org Iwebshop-5
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-08T17:48:32.728Z

Reserved: 2026-09-08T09:30:41.023Z

Link: CVE-2026-86667

cve-icon Vulnrichment

Updated: 2026-09-08T17:48:26.904Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T17:18:40.027

Modified: 2026-09-08T18:33:29.460

Link: CVE-2026-86667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:15:15Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')