CVE-2026-6982: star7th ShowDoc API Page Sort Endpoint PageController.class.PHP sql injection
A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file server/Application/Api/Controller/PageController.class.PHP of the component API Page Sort Endpoint. Executing a manipulation of the argument pages can lead to sql injection. The attack may be launched remotely. Upgrading to version 3.8.1 addresses this issue. It is suggested to upgrade the affected component. According to the researcher, "[t]he vendor explicitly stated they will not backport patches to the older affected versions."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
star7th ShowDoc API Page Sort Endpoint (PageController.class.PHP)to a version that resolves this vulnerability.Fixed in 3.8.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6982?
CVE-2026-6982 is classified as a critical severity SQL injection vulnerability that can allow an attacker to execute arbitrary SQL commands.
How do I fix CVE-2026-6982?
To fix CVE-2026-6982, upgrade the affected versions of star7th ShowDoc to the latest stable release that addresses this vulnerability.
Which versions of star7th ShowDoc are affected by CVE-2026-6982?
CVE-2026-6982 affects star7th ShowDoc versions up to and including 2.10.10, 3.6.2, and 3.8.0.
What type of attack can be executed through CVE-2026-6982?
CVE-2026-6982 allows an attacker to perform SQL injection attacks, potentially compromising the database.
Is CVE-2026-6982 remote executable?
Yes, CVE-2026-6982 can be exploited remotely, allowing attackers to manipulate database queries without physical access.