Executive brief
eMagicOne Store Manager is a tool used to manage e-commerce store data and inventory. A critical security flaw allows unauthorized individuals to perform blind SQL injection attacks against the store's database. This could lead to the theft of sensitive customer information, order history, and administrative credentials, potentially compromising the entire online retail operation.
Technical details
A Blind SQL Injection vulnerability exists in the eMagicOne Store Manager (specifically the WordPress connector plugin) due to improper neutralization of special elements used in SQL commands. The flaw is located in the handling of database queries, allowing an unauthenticated remote attacker to execute arbitrary SQL commands via the network. By sending specially crafted requests, an attacker can infer data from the database through boolean-based or time-based blind techniques. This vulnerability affects versions up to and including 1.3.2. The CVSS score of 9.3 reflects high confidentiality impact and the lack of required authentication.
Affected products
- eMagicOne Store Manager Connector up to 1.3.2
Timeline
- 2026-05-25: disclosed
- 2026-05-25: advisory