Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-ch7p-mpv4-4vg4 | CoreShop Vulnerable to SQL Injection via Admin Reports |
Mon, 12 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Coreshop
Coreshop coreshop |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:coreshop:coreshop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Coreshop
Coreshop coreshop |
Thu, 08 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques. The database account used by the application is read-only and non-DBA, limiting impact to confidential data disclosure only. No data modification or service disruption is possible. This issue has been patched in version 4.1.8. | |
| Title | CoreShop Vulnerable to SQL Injection via Admin Reports | |
| Weaknesses | CWE-564 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-08T14:26:19.902Z
Reserved: 2026-01-07T05:19:12.920Z
Link: CVE-2026-22242
Updated: 2026-01-08T14:26:10.948Z
Status : Analyzed
Published: 2026-01-08T10:15:56.127
Modified: 2026-01-12T16:42:51.783
Link: CVE-2026-22242
No data.
OpenCVE Enrichment
Updated: 2026-04-18T07:45:24Z
Github GHSA