Sceawere
Vulnerability Detail
CVE-2026-105149UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
mooSocial SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 3h ago
- Vendor
- n/a
- Product
- mooSocial
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-04T13:16:55.923Z",
"pubdate": "2026-10-04T13:16:55.923Z",
"executiveSummary": "A critical SQL injection vulnerability exists in mooSocial versions up to 3.2.4. The flaw originates from improper input sanitization of the 'rating' argument within the '/stores/all-products' file.\nThis vulnerability allows remote, unauthenticated attackers to execute arbitrary SQL commands against the application's backend database.\nThe impact of a successful exploit is severe, potentially resulting in unauthorized data exfiltration, modification of database contents, or full compromise of the application's data layer.\nThe vulnerability is currently public, and the vendor has remained unresponsive to disclosure attempts, increasing the risk of exploitation by malicious actors.\nThe flaw allows remote execution without requiring prior authentication or administrative privileges, presenting a high risk to the confidentiality and integrity of the affected platform.",
"technicalDetails": "The vulnerability is classified as a classic SQL Injection (SQLi), arising from the failure to properly sanitize user-supplied input before incorporating it into database queries. Specifically, the processing logic within the '/stores/all-products' file fails to parameterize the 'rating' argument.\nWhen a request is made to this endpoint, the application receives the 'rating' parameter and concatenates it directly into a database query string. An attacker can manipulate this parameter to inject arbitrary SQL syntax, thereby altering the query's logic and structure.\nThe attack flow begins with the adversary crafting a malicious HTTP request directed at the target URL. By injecting SQL meta-characters (such as single quotes, comments, or logical operators like 'OR 1=1') into the 'rating' argument, the attacker can force the database to execute unintended operations. For example, an attacker can use UNION-based techniques to extract data from other tables, or utilize blind SQL injection to infer data content based on application responses.\nThe vulnerable component is the script responsible for handling product rating queries within the '/stores/all-products' path. Since this input validation failure occurs at the application layer, the database server executes the injected statements with the privileges of the database user configured for the mooSocial application. If these privileges are overly permissive, the impact is significantly heightened.\nThe exploit can be initiated remotely, requiring no interaction from a privileged user. Because the vulnerability is public and the vendor has not provided a patch, the exposure window for affected installations is substantial. The exploit does not require authentication, meaning any user or bot with network access to the target web server can leverage this vulnerability.\nPost-exploitation, the impact includes full access to the database's contents, including user credentials, configuration data, and sensitive business information. Furthermore, depending on the database configuration, an attacker might be able to escalate the attack to read/write files on the underlying server or execute system-level commands, leading to complete server compromise."
}