216.73.217.80

CVE-2026-23959

· Published 22/01/2026 03:15 · Modified 22/01/2026 03:15

Labels: CVE-2026-23959 2026-01-22CVE-2026-23959CWE-564[email protected]

Essential information

Published
22/01/2026 03:15
Modified
22/01/2026 03:15
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions prior to 4.1.9 in the `CustomerTransformerController` within the CoreShop admin panel. The affected endpoint improperly interpolates user-supplied input into a SQL query, leading to database error disclosure and potential data extraction. Version 4.1.9 fixes the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pimcore / coreshop cpe:2.3:a:pimcore:coreshop:<4.1.9:*:*:*:*:*:*:*

References