
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-47763 is a SQL injection vulnerability in the Aimeos Laravel e-commerce platform (version 2021.10 LTS) affecting the sort parameter of the JSON API. Unauthenticated attackers can send crafted GET requests to the jsonapi/review endpoint to inject malicious database queries and extract sensitive schema information such as table and column names. The vulnerability was published to NVD on January 15, 2026, and carries a CVSS v3.1 base score of 8.2 (High) and a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, NVD).
The root cause is improper neutralization of special elements in an SQL command (CWE-89), where user-supplied input to the sort parameter is incorporated into database queries without adequate sanitization or parameterization. An attacker can exploit this by sending a crafted HTTP GET request to the /jsonapi/review endpoint with a malicious sort value, causing the backend to execute attacker-controlled SQL fragments. No authentication, special privileges, or user interaction is required, and attack complexity is low. A public exploit is referenced on Exploit-DB (EDB-50538) (NVD, GitHub Advisory).
Successful exploitation allows unauthenticated remote attackers to extract sensitive database metadata, including table and column names, and potentially enumerate or exfiltrate application data stored in the underlying database. The primary impact is high confidentiality loss, with a low integrity impact (e.g., potential for unauthorized data modification depending on database permissions), and no direct availability impact. Depending on the database user's privileges, further exploitation could enable broader data exfiltration, credential harvesting from the database, or lateral movement within the application's data layer (GitHub Advisory, NVD).
A public exploit for this vulnerability is listed on Exploit-DB (exploit ID 50538), indicating that weaponized proof-of-concept code is publicly available (NVD). The EPSS score is approximately 0.02–0.033%, placing it in the lower percentiles for near-term exploitation probability. No confirmed in-the-wild exploitation or specific threat actor attribution has been reported at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
/jsonapi/review endpoint./jsonapi/review?sort=id to confirm the endpoint responds normally and the application is potentially vulnerable.sort parameter value containing SQL injection syntax (e.g., sort=id,(SELECT+1+FROM+(SELECT+SLEEP(5))a)) to test for time-based blind SQL injection, or use UNION-based payloads to extract data.sort=id,(SELECT+table_name+FROM+information_schema.tables+LIMIT+1)).sqlmap -u 'https://target/jsonapi/review?sort=id' --dbs to systematically enumerate and dump database contents (NVD, GitHub Advisory)./jsonapi/review with abnormal or encoded sort parameter values (e.g., containing SQL keywords like SELECT, UNION, FROM, SLEEP, information_schema); high volume of requests to this endpoint from a single IP./jsonapi/review?sort= with SQL syntax fragments; database error messages logged related to malformed SQL queries; unusually long query execution times suggesting time-based blind SQL injection.information_schema.tables or information_schema.columns in database query logs; queries returning large volumes of schema metadata.The GitHub Advisory (GHSA-hm9j-cgmm-2w36) notes that no patched version has been formally listed for the aimeos/aimeos-laravel 2021.10 LTS package; users should upgrade to a newer supported release of Aimeos that addresses this issue (GitHub Advisory). As interim mitigations, restrict access to the /jsonapi/review endpoint using network-level controls or web application firewall (WAF) rules that block SQL injection patterns in the sort parameter. Review and audit database user permissions to enforce least privilege, limiting the damage potential of any successful injection. Monitor database and application logs for anomalous query patterns indicative of exploitation attempts.
The vulnerability received automated coverage from security aggregators including RedPacket Security and CVEFeed shortly after its NVD publication in January 2026. A technical write-up was published at infinitsec.net detailing the vulnerability. The CISA weekly vulnerability bulletin (SB26-020) for the week of January 12, 2026 referenced this CVE. No notable vendor statements or significant researcher commentary beyond automated aggregation have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."