Junglewise Threat Intelligence

CVE-2026-38808: uzy-ssm-mall SQL injection in orderBy parameter

CVE-2026-38808 · Severity: info · CVSS 7.5 · Published 2026-05-27

Executive brief

uzy-ssm-mall is an e-commerce platform. A security vulnerability in its product listing and administrative components allows unauthorized individuals to perform SQL injection attacks. By sending specially crafted web requests, an attacker can bypass security controls to access sensitive database information, including customer data and system configurations, without needing to log in.

Technical details

A SQL injection vulnerability exists in uzy-ssm-mall v1.1.0 due to improper neutralization of the 'orderBy' parameter. The application uses MyBatis for data persistence and utilizes the '${}' syntax for dynamic string concatenation in ProductMapper.xml, UserMapper.xml, and ProductOrderMapper.xml. Because the 'orderBy' input from OrderUtil.java is concatenated directly into the ORDER BY clause without whitelist validation or parameterization, a remote attacker can inject arbitrary SQL fragments. This can be exploited via unauthenticated endpoints such as '/mall/product/{index}/{count}' or authenticated administrative endpoints to perform time-based blind SQL injection and extract database contents.

Affected products

  • ghostxbh uzy-ssm-mall 1.1.0

Timeline

  • 2026-04-01: disclosed: Vulnerability details shared on GitHub issues
  • 2026-05-27: advisory: CVE published to NVD

References