SQL Injection Vulnerability in Modulithshop by shsuishang
CVE-2026-5328
Key Information:
- Vendor
Shsuishang
- Status
- Vendor
- CVE Published:
- 2 April 2026
Badges
What is CVE-2026-5328?
A vulnerability has been detected in Modulithshop, specifically within the ProductItemDao interface, that allows attackers to exploit a SQL injection flaw through manipulation of the 'sidx' or 'sort' arguments. This issue is present in the file stored at src/main/java/com/suisung/shopsuite/pt/service/impl/ProductIndexServiceImpl.java and can be executed remotely, leading to potential unauthorized access or data manipulation. Publicly available exploits may compound the risk. To mitigate this vulnerability, it is crucial to apply the provided patch (commit ID: 42bcb9463425d1be906c3b290cf29885eb5a2324) as soon as possible.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
modulithshop 829bac71f507e84684c782b9b062b8bf3b5585d6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
