Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based injection payloads to extract arbitrary database contents including user password hashes from the tl_user table.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 15:00:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-23T16:03:27.808Z
Reserved: 2026-09-23T13:44:02.364Z
Link: CVE-2026-96600
Updated: 2026-09-23T16:03:24.152Z
Status : Received
Published: 2026-09-23T15:17:33.400
Modified: 2026-09-23T15:17:33.400
Link: CVE-2026-96600
No data.
OpenCVE Enrichment
No data.
Weaknesses