Executive brief
Craft Commerce, an e-commerce platform for Craft CMS, is vulnerable to a security flaw that allows authorized users with control panel access to extract sensitive information from the database. By exploiting this vulnerability, an attacker could gain full access to customer data or escalate their own privileges to become a full administrator. This could lead to a complete compromise of the online store and its underlying data.
Technical details
A blind SQL injection vulnerability exists in Craft Commerce due to improper sanitization of the 'hasVariant' and 'hasProduct' properties within ProductQuery and VariantQuery. While top-level Yii2 Query properties were previously blocklisted in ElementIndexesController, these specific subquery properties bypass the filter and are passed to Craft::configure() without validation. An authenticated control panel user can exploit this by injecting SQL into the 'where' clause of these subqueries (e.g., via criteria[hasVariant][where]=...). This allows for boolean-based blind SQL injection to extract arbitrary database data, including security keys used for session forgery. The issue is fixed in version 5.6.0.
Affected products
- Craft CMS Commerce >= 5.0.0, < 5.6.0
Timeline
- 2026-04-13: patched: Fixed in version 5.6.0
- 2026-04-14: disclosed: GitHub Advisory published