CVE-2026-5328 describes a remote SQL injection vulnerability in the shsuishang modulithshop application, specifically affecting the listItem function within the ProductItemDao Interface component up to commit 829bac71f507e84684c782b9b062b8bf3b5585d6. This Medium severity (CVSS 6.3) flaw has a low attack complexity and requires low privileges, allowing an attacker to manipulate the sidx/sort argument for potential limited impact on confidentiality, integrity, and availability. Public exploit code is available for this vulnerability, which is also noted on the "Hot List: Active," indicating an elevated risk of exploitation despite not being in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Shsuishang | Modulithshop | 829bac71f507e84684c782b9b062b8bf3b5585d6CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.