Executive brief
Likeshop, an e-commerce management platform, contains a security flaw in its account adjustment feature. An administrator with access to the management console can exploit this to bypass security controls and extract sensitive information from the underlying database. This could lead to the theft of customer personal data, login credentials, and session tokens, potentially compromising the entire store operations.
Technical details
An authenticated SQL injection vulnerability exists in Likeshop versions up to and including 3.0.5 within the adjustAccount method of UserLogic.php. The application fails to sanitize or type-cast the 'money', 'integral', 'growth', and 'earnings' POST parameters before concatenating them directly into Db::raw() SQL fragments. Because the application returns distinct success or failure messages based on whether the SQL execution triggers an error, an attacker with administrative privileges can perform boolean-based binary-search extraction of database contents. This allows for the exfiltration of sensitive data such as PII and credentials. Remediation requires casting input parameters to numeric types or using parameterized queries instead of raw string concatenation.
Affected products
- likeadmin-likeshop Likeshop <= 3.0.5
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory