SQL Injection Vulnerability in Abdurrab5 Online Makeup Store Admin Login
CVE-2026-96601

6.9MEDIUM

Key Information:

Vendor

Abdurrab5

Vendor
CVE Published:
23 September 2026

What is CVE-2026-96601?

A vulnerability exists in the Abdurrab5 online makeup store's Admin Login Handler, specifically within the index.php file. This issue allows for SQL injection via manipulation of the id/password parameters, potentially leading to unauthorized access to sensitive data. The exploit can be executed remotely, making it critical for users to apply necessary security measures. A public exploit for this vulnerability has been made available, and the vendor has been previously informed about the disclosure.

Affected Version(s)

online-makeup-store 336a4b09e5c840bdfe6dfde6616add0b20e4b4ee

online-makeup-store c3ca96769c008a8a1518c8f9adbc7c8b52d83480

online-makeup-store f804fe3ef5cf3570ced0fa34fb2de492a1306345

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yashkumar Keral (VulDB User)
VulDB CNA Team
.