Tenable
SureCart SQL Injection Vulnerability Discovered in Version 4.1.0
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
SureCart versions 4.1.0 and earlier are vulnerable to authenticated SQL injection through multiple parameters on the REST API endpoint '/surecart/v1/integrations/{id}'. The vulnerability arises from a flawed escaping bypass in the query builder, allowing attackers to inject arbitrary SQL by including a dot in the payload. This can lead to full UNION-based extraction of the database. Users are advised to upgrade to SureCart version 4.2.1 or later to mitigate the risk. The vulnerability affects any installation of SureCart that has not been updated. Tenable has emphasized the importance of addressing this issue promptly to protect customers. The advisory does not provide a CVE identifier, but it highlights the critical nature of the flaw.
Key Points: • SureCart versions 4.1.0 and earlier are vulnerable to SQL injection. • Attackers can exploit the flaw by including a dot in the payload. • Users must upgrade to version 4.2.1 or later to mitigate the risk.