GHSA-7pjx-8r2g-hwppHighCVSS 5.5
Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend...
🔗 CVE IDs covered (1)
📋 Description
Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based injection payloads to extract arbitrary database contents including user password hashes from the tl_user table.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-96600
- https://github.com/isotope/core/issues/2585
- https://github.com/isotope/core
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modules/isotope/library/Isotope/Backend/Attribute/Callback.php#L186-L188
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modules/isotope/library/Isotope/Backend/Attribute/Callback.php#L38
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modules/isotope/library/Isotope/Backend/ProductPrice/Callback.php#L155-L200
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modules/isotope/library/Isotope/Widget/MediaManager.php#L468
- https://www.vulncheck.com/advisories/isotope-ecommerce-through-2.9.10-sql-injection-via-backend-callbacks
- https://github.com/advisories/GHSA-7pjx-8r2g-hwpp