Blind SQL Injection Vulnerability in CoreShop eCommerce Solution
CVE-2026-22242

4.9MEDIUM

Key Information:

Vendor

Coreshop

Status
Vendor
CVE Published:
8 January 2026

What is CVE-2026-22242?

CoreShop, an enhanced eCommerce solution for Pimcore, has a vulnerability that allows authenticated administrator-level users to execute blind SQL injection attacks. This can lead to the unauthorized extraction of sensitive database information using either boolean-based or time-based techniques. The vulnerability exists due to the application using a read-only and non-DBA database account, which prevents data modification or service disruption. It is critical to update to version 4.1.8 or later to mitigate this risk.

Affected Version(s)

CoreShop < 4.1.8

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.