SureCart SQL Injection Vulnerability Discovered in Version 4.1.0

SureCart SQL Injection Vulnerability Discovered in Version 4.1.0

First seen 20 May 2026, 12:38 UTC Tenable 99% similarity 57.8

Article Content

Browse articles
ThreatCluster

SureCart versions 4.1.0 and earlier are vulnerable to authenticated SQL injection through multiple parameters on the REST API endpoint '/surecart/v1/integrations/{id}'. The vulnerability arises from a flawed escaping bypass in the query builder, allowing attackers to inject arbitrary SQL by including a dot in the payload. This can lead to full UNION-based extraction of the database. Users are advised to upgrade to SureCart version 4.2.1 or later to mitigate the risk. The vulnerability affects any installation of SureCart that has not been updated. Tenable has emphasized the importance of addressing this issue promptly to protect customers. The advisory does not provide a CVE identifier, but it highlights the critical nature of the flaw.

Key Points: • SureCart versions 4.1.0 and earlier are vulnerable to SQL injection. • Attackers can exploit the flaw by including a dot in the payload. • Users must upgrade to version 4.2.1 or later to mitigate the risk.

ThreatCluster AI

Timeline

2026-05-20
Vulnerability disclosed
Tenable published an advisory detailing an SQL injection vulnerability in SureCart versions 4.1.0 and earlier.
Tenable
2026-05-20
Upgrade recommended
Tenable advised users to upgrade to SureCart version 4.2.1 or later to address the vulnerability.
Tenable

Community

Browse all →

Tracked Entities in This Story