Blind SQL Injection Vulnerability in CoreShop eCommerce Solution
CVE-2026-22242
4.9MEDIUM
What is CVE-2026-22242?
CoreShop, an enhanced eCommerce solution for Pimcore, has a vulnerability that allows authenticated administrator-level users to execute blind SQL injection attacks. This can lead to the unauthorized extraction of sensitive database information using either boolean-based or time-based techniques. The vulnerability exists due to the application using a read-only and non-DBA database account, which prevents data modification or service disruption. It is critical to update to version 4.1.8 or later to mitigate this risk.
Affected Version(s)
CoreShop < 4.1.8
