CVE-2026-14799: SQL Injection in CodeAstro Ecommerce Website 1.0 Customer Wishlist
CodeAstro Ecommerce Website version 1.0 contains a SQL injection vulnerability in its customer account management functionality. An authenticated attacker can manipulate the delete_wishlist parameter in the /customer/my_account.php?my_wishlist endpoint to execute arbitrary SQL commands against the application's database. The flaw requires valid login credentials but no elevated privileges, and can be exploited over the network. Public exploit code exists, increasing the risk of active attacks.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-74, CWE-89
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-06 / 2026-07-06
NVD description (verbatim)
A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability resides in improper input validation within the wishlist deletion feature of CodeAstro Ecommerce Website 1.0. The delete_wishlist parameter fails to sanitize or parameterize user input before passing it to SQL queries, enabling classic SQL injection attacks. The vulnerability is classified under CWE-74 (Improper Neutralization of Special Elements in Output) and CWE-89 (SQL Injection), reflecting both the input handling and database-layer exploitation vectors. Authentication is required to reach the vulnerable code path, limiting attack surface to users with valid customer accounts.
Business impact
Organizations running CodeAstro Ecommerce Website 1.0 face direct threats to customer data confidentiality and integrity. Attackers with customer credentials can read sensitive customer records, modify wishlist data, or potentially access payment and personal information stored in the database. Data manipulation could undermine customer trust and create compliance exposure under data protection regulations. The public availability of exploit code elevates the probability of opportunistic attacks.
Affected systems
CodeAstro Ecommerce Website version 1.0 is the confirmed affected product. No patch version or newer releases were specified in available data; organizations should verify whether CodeAstro has released patches or recommend upgrading to a patched version by contacting the vendor directly or checking their security advisories.
Exploitability
The vulnerability is readily exploitable. It requires network access and valid customer account credentials, but no special privileges or user interaction beyond crafting a malicious request. The CVSS 3.1 score of 6.3 (Medium severity) reflects this balance: network accessibility and straightforward exploitation technique are offset by the authentication requirement. Publicly disclosed exploit code significantly increases real-world exploitation likelihood; defenders should assume active reconnaissance and attack attempts are underway.
Remediation
Immediate actions include: (1) contact CodeAstro for security patches or workarounds; (2) if patched versions are available, prioritize testing and deployment to production environments; (3) implement database access controls and prepared statement practices throughout the application codebase; (4) conduct code review of all user input handling in database interactions; (5) enable database activity logging to detect exploitation attempts; (6) restrict access to the /customer/my_account.php endpoint at the network or WAF layer if updates cannot be deployed immediately.
Patch guidance
Verify the CodeAstro Ecommerce Website vendor advisory for available patches. Given the publication date of this CVE (July 6, 2026), contact CodeAstro support or monitor their security page for a patched release. If version 1.0 remains the current product line, push for an expedited security release. Test any patches in a non-production environment before rollout, as they may affect wishlist functionality or related features.
Detection guidance
Monitor web application logs for suspicious activity in the /customer/my_account.php endpoint, particularly requests containing SQL metacharacters (', ", --, ;, or /*) in the delete_wishlist parameter. Database query logs should be reviewed for unexpected or malformed SQL statements originating from the wishlist deletion routine. Implement network intrusion detection rules to identify SQL injection patterns targeting this endpoint. Web application firewalls should be configured to block requests with SQL injection payloads in the delete_wishlist parameter.
Why prioritize this
While the CVSS score is Medium (6.3), this vulnerability warrants priority patching due to the combination of: (1) publicly available exploit code lowering the bar for attacker skill; (2) direct database access through SQL injection, enabling wholesale data theft or manipulation; (3) ecommerce context where customer data is high-value; (4) authentication requirement limiting but not eliminating risk, as customer credentials are widely available through credential stuffing or insider threats. Organizations operating ecommerce platforms should treat this as a near-term fix.
Risk score, explained
The CVSS 3.1 score of 6.3 (Medium) reflects: (1) network-accessible attack vector (AV:N) — anyone on the internet can attempt exploitation; (2) low attack complexity (AC:L) — no special conditions or tools required; (3) low privilege requirement (PR:L) — valid customer login only, not administrative access; (4) no user interaction needed (UI:N); (5) unchanged scope (S:U); (6) low impact across confidentiality, integrity, and availability (C:L/I:L/A:L) — the attacker can read and modify data but cannot directly crash the service or deny availability. The score reflects a contained but meaningful risk, elevated in practice by exploit availability.
Frequently asked questions
Do we need administrative access to exploit this vulnerability?
No. The vulnerability requires only valid customer account credentials. An attacker with a legitimate or compromised customer login can exploit it. If your organization uses shared customer accounts or has weak credential management, the effective risk increases.
What data is at risk if this vulnerability is exploited?
Any data accessible to the application's database connection can potentially be read or modified via SQL injection. This typically includes customer profiles, order history, payment information, and wishlist records. The attacker's ability to access other database tables depends on the database user permissions and schema design.
Can this vulnerability cause a denial of service or crash the application?
SQL injection primarily enables data exfiltration and modification. However, poorly crafted payloads could potentially consume database resources or cause errors. The CVSS impact rating (Low) reflects that direct denial of service is not the primary concern; data breach and manipulation are the main risks.
Is there a workaround if we cannot patch immediately?
Temporary mitigations include: (1) blocking or rate-limiting access to /customer/my_account.php at your WAF or firewall; (2) disabling the wishlist feature if it is not critical; (3) implementing database activity monitoring to detect and alert on exploitation attempts; (4) restricting customer account creation; (5) forcing password resets to invalidate stolen credentials. None of these fully resolve the vulnerability—patching is the proper fix.
This analysis is based on publicly available CVE data and vendor information current as of the publication date. No exploit code or proof-of-concept demonstrations are provided. Organizations should verify patch availability directly with CodeAstro and test any updates in a non-production environment before deployment. Risk assessments and business impact may vary based on individual system configurations, data exposure, and regulatory obligations. This document does not constitute security advice; consult with your security team or a professional service provider for organization-specific guidance. Source: NVD (public-domain), retrieved 2026-08-14. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10155MEDIUMSQL Injection in Bdtask Multi-Store Inventory Management System 1.0
- CVE-2026-10170MEDIUMSQL Injection in code-projects Visitor Management System 1.0
- CVE-2026-10171MEDIUMSQL Injection in code-projects Online Music Site 1.0 AdminUpdateAlbum.php
- CVE-2026-10176MEDIUMSQL Injection in Aider-AI Aider 0.86.3 Code Generation
- CVE-2026-10193MEDIUMSQL Injection in OFCMS ComnController – Authentication Required
- CVE-2026-10202MEDIUMOFCMS 1.1.3 SQL Injection in SystemDictController
- CVE-2026-10203MEDIUMSQL Injection in OFCMS 1.1.3 JSON Query Interface
- CVE-2026-10204MEDIUMSQL Injection in OFCMS 1.1.3 JSON Query Interface