GHSA-hm9j-cgmm-2w36

Suggest an improvement
Source
https://github.com/advisories/GHSA-hm9j-cgmm-2w36
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-hm9j-cgmm-2w36/GHSA-hm9j-cgmm-2w36.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hm9j-cgmm-2w36
Aliases
  • CVE-2021-47763
Published
2026-01-15T18:31:30Z
Modified
2026-02-03T03:26:18Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Aimeos contains a SQL injection vulnerability in the json api 'sort' parameter
Details

Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries. Attackers can manipulate the sort parameter to reveal table and column names by sending crafted GET requests to the jsonapi/review endpoint.

Database specific
{
    "cwe_ids":  [
        "CWE-89"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-01-15T22:38:52Z",
    "nvd_published_at":  "2026-01-15T16:16:07Z",
    "severity":  "HIGH"
}
References

Affected packages

Packagist / aimeos/aimeos-laravel

Package

Name
aimeos/aimeos-laravel
Purl
pkg:composer/aimeos/aimeos-laravel

Affected ranges

Affected versions

2021.*
2021.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-hm9j-cgmm-2w36/GHSA-hm9j-cgmm-2w36.json"