CVE-2026-96602: Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection
A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of Abdurrab5 online-makeup-store that expose the customer login handler through customerSignin.php are potentially exposed. The attack can be performed remotely and requires no privileges or user interaction.
What input is involved in exploitation?
The vulnerable inputs are the username and password arguments handled by customerSignin.php. Manipulating these values can lead to SQL injection in the Customer Login Handler.
How likely is active exploitation?
A public exploit has been published and may be used. The issue has a high severity rating, with low attack complexity and network-based attack vector.
Which versions are affected or fixed?
Specific affected and fixed versions are not available because the product uses a rolling release strategy. The provided data does not identify a version boundary for remediation.