Executive brief
ReadyEcommerce is an e-commerce platform used to build online stores with multi-vendor support. An unauthenticated SQL injection vulnerability in the product listing API allows attackers to directly query the database without authentication, potentially exposing customer data, user credentials, and administrator password hashes. The database runs as root, creating additional risk for file system access and complete system compromise.
Technical details
The vulnerability is a SQL injection flaw (CWE-89) in the ProductController.php file where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization or input validation. An unauthenticated attacker on the network can perform time-based blind SQL injection attacks through this unsanitized rating parameter to extract the full database contents. The database connection runs with root privileges, which could allow an attacker to leverage database functionality (such as INTO OUTFILE) to write files to the filesystem. The vulnerability affects ReadyEcommerce versions before 4.5.2; patching to 4.5.2 or later resolves the issue.
Affected products
- ReadyEcommerce ReadyEcommerce before 4.5.2
Timeline
- 2026-08-10: disclosed