2026-09-23 21:15CVE-2026-96602VulDB
PUBLISHED5.2ApplicationCWE-89CWE-74

Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection

A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure.

Problem type

Affected products

Abdurrab5

online-makeup-store

336a4b09e5c840bdfe6dfde6616add0b20e4b4ee - AFFECTED

c3ca96769c008a8a1518c8f9adbc7c8b52d83480 - AFFECTED

f804fe3ef5cf3570ced0fa34fb2de492a1306345 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-96602
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-96602",
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "dateUpdated": "2026-09-23T21:15:07.900Z",
    "dateReserved": "2026-09-23T13:46:25.799Z",
    "datePublished": "2026-09-23T21:15:07.900Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB",
        "dateUpdated": "2026-09-23T21:15:07.900Z"
      },
      "title": "Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection",
      "descriptions": [
        {
          "lang": "en",
          "value": "A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure."
        }
      ],
      "affected": [
        {
          "vendor": "Abdurrab5",
          "product": "online-makeup-store",
          "cpes": [
            "cpe:2.3:a:abdurrab5:online-makeup-store:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Customer Login Handler"
          ],
          "versions": [
            {
              "version": "336a4b09e5c840bdfe6dfde6616add0b20e4b4ee",
              "status": "affected"
            },
            {
              "version": "c3ca96769c008a8a1518c8f9adbc7c8b52d83480",
              "status": "affected"
            },
            {
              "version": "f804fe3ef5cf3570ced0fa34fb2de492a1306345",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "SQL Injection",
              "cweId": "CWE-89",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Injection",
              "cweId": "CWE-74",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://vuldb.com/vuln/408968",
          "name": "VDB-408968 | Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection",
          "tags": [
            "vdb-entry",
            "technical-description"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/408968/cti",
          "name": "VDB-408968 | CTI Indicators (IOB, IOC, TTP, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-96602",
          "name": "CVE-2026-96602 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/898998",
          "name": "Submit #898998 | Abdurrab5 (Github) Online Makeup Store 1.0 Unauthenticated SQL Injection (Authentication Bypass)",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/yashkeral/cve-writeups/blob/main/online-makeup-store/02-customer-login-sqli.md",
          "tags": [
            "exploit"
          ]
        }
      ],
      "metrics": [
        {},
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
            "baseScore": 7.3,
            "baseSeverity": "HIGH"
          }
        },
        {
          "cvssV3_0": {
            "version": "3.0",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
            "baseScore": 7.3,
            "baseSeverity": "HIGH"
          }
        },
        {
          "cvssV2_0": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
            "baseScore": 7.5
          }
        }
      ],
      "timeline": [
        {
          "time": "2026-09-23T00:00:00.000Z",
          "lang": "en",
          "value": "Advisory disclosed"
        },
        {
          "time": "2026-09-23T02:00:00.000Z",
          "lang": "en",
          "value": "VulDB entry created"
        },
        {
          "time": "2026-09-23T15:53:03.000Z",
          "lang": "en",
          "value": "VulDB entry last update"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Yashkumar Keral (VulDB User)",
          "type": "reporter"
        },
        {
          "lang": "en",
          "value": "VulDB CNA Team",
          "type": "coordinator"
        }
      ]
    }
  }
}