Executive brief
A security vulnerability exists in the CodeAstro Ecommerce Website, a platform used for online retail operations. An attacker with a customer account can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the theft of sensitive customer information, tampering with website data, or disruption of the online store's services.
Technical details
A SQL injection vulnerability exists in CodeAstro Ecommerce Website 1.0 within the '/ecommerce-website-php/customer/my_account.php' file. The root cause is the improper neutralization of the 'c_name' POST parameter when processing account edits (edit_account). An attacker with low-privileged user credentials can submit a specially crafted multipart form-data request containing SQL payloads, such as time-based blind injection strings. Successful exploitation allows for unauthorized database queries, potentially leading to data exfiltration or modification. A public exploit (PoC) has been disclosed, and the vendor has not yet released a formal patch; users are advised to implement prepared statements and parameter binding manually.
Affected products
- CodeAstro Ecommerce Website 1.0
Timeline
- 2026-06-02: disclosed: Public issue opened on GitHub with PoC details
- 2026-07-04: advisory: CVE published to NVD dataset