Local File Disclosure Vulnerability in InnoShop by InnoCommerce
CVE-2026-108591
5.9MEDIUM
What is CVE-2026-108591?
InnoShop version 0.9.2 is susceptible to a local file disclosure vulnerability that affects authenticated administrators with specific permissions. By leveraging the AI Core MCP file_upload tool, attackers can manipulate the source argument, allowing them to use 'file://' or 'php://' stream wrappers with functions such as file_get_contents(). This enables the unauthorized reading of sensitive server files, including the critical .env file that contains the application key and database credentials, thereby exposing sensitive data and increasing the risk of further exploitation.
Affected Version(s)
InnoShop 0.9.2
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
