Critical 9.1 SQL Injection Threatens Vendure Core Stores
ID: 9fd536d5-5fbc-5c2a-a881-23ce79563cb3
STIX ID: report--9fd536d5-5fbc-5c2a-a881-23ce79563cb3
Feed Name: securityonline.info
Threat Score
Vendure Core released patches for a critical SQL injection vulnerability (CVSS 9.1) in how the languageCode parameter is handled; an unauthenticated attacker can exploit the Shop API to execute arbitrary SQL across all supported database backends. Multiple release lines are affected and fixed releases plus a suggested input-validation hotfix are provided to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
