Sceawere

Vulnerability Detail

CVE-2026-108541UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Super Store Finder SQL Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
highwarden
Product
Super Store Finder
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in highwarden Super Store Finder up to 3.8. Affected is an unknown function of the file /products/superstorefinder/index.php. The manipulation of the argument lat/lng leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 3.9 is able to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-11T07:17:23.700Z",
  "pubdate": "2026-10-11T07:17:23.700Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the Super Store Finder plugin for versions up to 3.8. The vulnerability exists within the /products/superstorefinder/index.php component, specifically originating from improper sanitization of user-supplied input provided via the 'lat' and 'lng' arguments.\nThis flaw allows remote, unauthenticated attackers to manipulate SQL queries by injecting malicious SQL commands, potentially leading to unauthorized data exfiltration, modification, or complete database compromise. Given that the exploit code has been publicly disclosed, the risk of active exploitation is significant.\nAffected systems are susceptible to full database interrogation, which may expose sensitive store data, configuration details, or administrative credentials. Organizations utilizing this product are strongly advised to prioritize upgrading to version 3.9 immediately to mitigate this risk. The vendor has acknowledged the issue and provided a patch, making the upgrade the primary and required remediation step.",
  "technicalDetails": "The vulnerability is classified as a SQL injection (SQLi) flaw residing within the application's backend logic. Specifically, the file /products/superstorefinder/index.php fails to implement adequate input validation or parameterization on the 'lat' (latitude) and 'lng' (longitude) parameters before passing them into database query execution functions.\nThe root cause is the improper handling of user-controllable input within the SQL context. When an attacker submits crafted values for the 'lat' or 'lng' parameters, the application concatenates this input directly into an SQL statement. Because these inputs are not treated as literal data, the SQL engine interprets the malicious input as executable query logic.\nExploitation is possible remotely without requiring authentication. An attacker can craft HTTP requests containing malicious payloads within the vulnerable parameters. The attack flow generally involves the attacker sending an HTTP GET or POST request to the affected index.php endpoint. By appending SQL syntax—such as UNION-based injection, error-based techniques, or boolean-based blind SQL injection—to the 'lat' or 'lng' arguments, the attacker can manipulate the query structure.\nFor instance, an attacker could terminate the intended query and append a secondary query to extract data from system tables, bypass authentication, or even execute administrative commands depending on the database user permissions and backend configuration. The payload is interpreted by the database management system (DBMS) at the server level, granting the attacker control over the interaction with the underlying data repository.\nThe scope of impact is broad, extending to the integrity and confidentiality of the entire database managed by the application. Successful exploitation results in the exposure of sensitive application data, potential unauthorized access to administrative functions, or the ability to modify core application settings. The lack of proper parameterized queries or prepared statements is the fundamental defect that enables this vulnerability across all versions up to 3.8."
}
CVE-2026-108541: Super Store Finder SQL Injection (MEDIUM Severity, CVSS: 6.3) | Sceawere