CVE-2026-42773
eMagicOne Store Manager versions up to 1.3.2 contain a blind SQL injection flaw that lets attackers send crafted input to the database without any user interaction. If exploited, the attacker could read or modify sensitive data stored by the application.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
eMagicOne Store Manager, versions 1.3.2 and earlier. Store owners and administrators running these versions are affected.
Real-world impact
An attacker could execute arbitrary SQL commands against the store’s database, potentially extracting customer information, altering orders, or deleting records. Because the injection is blind, the attacker may not see immediate output but can infer success through timing or other side‑channels.
Why this severity
The CVSS score of 9.3 reflects that the flaw is network‑exploitable, requires no authentication, and can lead to a complete loss of confidentiality. The impact on integrity is moderate and availability is low, but the lack of user interaction and the high confidentiality impact push the score into the critical range.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 25, 2026 · May 25, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.