Junglewise Threat Intelligence

CVE-2024-13149: Arma Store Armalife SQL injection

CVE-2024-13149 · Severity: critical · CVSS 9.8 · Published 2025-09-16

Executive brief

Arma Store Armalife is susceptible to a critical security flaw that allows unauthorized individuals to access and manipulate its underlying database. This could lead to the theft of sensitive customer information, the alteration of business records, or a complete disruption of the service. As of the latest report, the vendor has not confirmed a fix for this issue, posing a significant risk to data integrity and privacy.

Technical details

A SQL injection vulnerability exists in Arma Store Armalife through version 20250916 due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to execute arbitrary SQL queries against the backend database via the network. Successful exploitation can result in the exposure of sensitive information (CWE-200), unauthorized modification of data, or a total loss of availability. At the time of disclosure, a patch had not been confirmed by the vendor.

Affected products

  • Arma Store Armalife through 20250916

Timeline

  • 2025-09-16: disclosed: Initial disclosure by USOM/CERT-TR
  • 2025-09-16: advisory: NVD publication date

References