Impact
Isotope eCommerce through 2.9.10 introduces a blind SQL injection vulnerability within backend callbacks that truthfully interpolates request-controlled identifiers and administrator supplied values into SQL statements. This flaw permits authorized Contao backend users with Isotope module permissions to inject conditional and time‑based payloads, leading to extraction of arbitrary database contents, including user password hashes from the tl_user table. The vulnerability falls under CWE‑89 and can severely compromise confidentiality of stored credentials.
Affected Systems
The issue impacts installations of Isotope eCommerce up to and including version 2.9.10. All systems running this module and allowing backend access to Isotope module permissions are susceptible. No specific patch versions are listed in the input, so any system remaining on 2.9.10 or earlier must be considered vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7, indicating high severity. EPSS is not reported, so the real‑world exploitation likelihood is unknown, though the flaw remains in the public domain without a known exploit. The issue is not listed in the CISA KEV catalog. Attackers would need authenticated access within the Contao backend with Isotope permissions, making it an internal or privileged threat vector rather than a remote public-facing attack. Given the high impact of credential disclosure, it warrants swift remediation.
OpenCVE Enrichment