SQL Injection Vulnerability in Abdurrab5 Online Makeup Store's Customer Login Handler
CVE-2026-96602

6.9MEDIUM

Key Information:

Vendor

Abdurrab5

Vendor
CVE Published:
23 September 2026

What is CVE-2026-96602?

A security flaw has been identified in the Abdurrab5 online makeup store, specifically within the customerSignin.php file. This vulnerability affects the Customer Login Handler component and allows an attacker to manipulate the username and password arguments, potentially leading to SQL injection. Notably, this exploit can be executed remotely, making it particularly concerning. The vendor has adopted a rolling release strategy, which limits the specification of affected versions. A notice was sent to the vendor regarding this discovery.

Affected Version(s)

online-makeup-store 336a4b09e5c840bdfe6dfde6616add0b20e4b4ee

online-makeup-store c3ca96769c008a8a1518c8f9adbc7c8b52d83480

online-makeup-store f804fe3ef5cf3570ced0fa34fb2de492a1306345

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yashkumar Keral (VulDB User)
VulDB CNA Team
.