Impact
The flaw allows an attacker to inject arbitrary SQL through the Search argument of the member_list function in controllers/member.php. By crafting malicious input, an adversary can execute unintended SQL statements against the underlying database, potentially reading sensitive data, modifying records, or deleting information. This results in data confidentiality, integrity, and availability compromise.
Affected Systems
aircheng-org iWebShop-5 versions up to 5.15 are affected. Any deployment of this open‑source e‑commerce platform that has not applied a patch and still exposes the member_list endpoint is vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderately serious weakness. Although the EPSS score is not available, the vulnerability is publicly known and an exploit has been released, meaning remote actors can readily target it. It is not listed in CISA’s KEV catalog, so it is considered a general‑purpose issue rather than a known actively exploited exploit. Attackers only need to send a crafted request to the Search parameter, requiring no special privileges on the web server or database. In the absence of an official patch, the risk remains moderate to high for unmitigated instances.
OpenCVE Enrichment