CVE-2026-96602

Summary

A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure.

Affected Software

VendorProductVersion RangeStatus
Abdurrab5online-makeup-store336a4b09e5c840bdfe6dfde6616add0b20e4b4eeaffected
Abdurrab5online-makeup-storec3ca96769c008a8a1518c8f9adbc7c8b52d83480affected
Abdurrab5online-makeup-storef804fe3ef5cf3570ced0fa34fb2de492a1306345affected

Weaknesses

  • CWE-89: SQL Injection
  • CWE-74: Injection

References