Record summary

CVE-2021-47763 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries. Attackers can manipulate the sort parameter to reveal table and column names by sending crafted GET requests to the jsonapi/review endpoint.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 15, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Aimeos Laravel ecommerce platform

Browse Aimeos / Aimeos Laravel ecommerce platform
CVE ListAimeos 2021.10 LTSaffected
GitHub Advisory2021.10affected

Proofs of concept

1

Catalogued exploits

ExploitDBAimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injectionExploitDB exploitby Ilker Burak ADIYAMANNot analyzed1 file
ExploitDB

PoC details

References

5