CVE-2021-47763
Aimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries. Attackers can manipulate the sort parameter to reveal table and column names by sending crafted GET requests to the jsonapi/review endpoint.
| CWE | CWE-89 |
| Vendor | aimeos |
| Product | aimeos laravel ecommerce platform |
| Published | Jan 15, 2026 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for aimeos aimeos laravel ecommerce platform
Be the first to know when new high vulnerabilities affecting aimeos aimeos laravel ecommerce platform are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
Aimeos / Aimeos Laravel ecommerce platform
Aimeos 2021.10 LTS
References
Credits
Ilker Burak ADIYAMAN