Executive brief
Arma Store Armalife is susceptible to a critical security flaw that allows unauthorized individuals to access and manipulate its underlying database. This could lead to the theft of sensitive customer information, the alteration of business records, or a complete disruption of the service. As of the latest report, the vendor has not confirmed a fix for this issue, posing a significant risk to data integrity and privacy.
Technical details
A SQL injection vulnerability exists in Arma Store Armalife through version 20250916 due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to execute arbitrary SQL queries against the backend database via the network. Successful exploitation can result in the exposure of sensitive information (CWE-200), unauthorized modification of data, or a total loss of availability. At the time of disclosure, a patch had not been confirmed by the vendor.
Affected products
- Arma Store Armalife through 20250916
Timeline
- 2025-09-16: disclosed: Initial disclosure by USOM/CERT-TR
- 2025-09-16: advisory: NVD publication date