CVE-2026-59550
AWP Classifieds versions up to 4.4.7 are vulnerable to an unauthenticated SQL injection. The flaw allows attackers to send crafted input that is executed directly by the database, potentially exposing or altering data. The vulnerability is critical because it can be exploited without authentication and can lead to significant data compromise.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
AWP Classifieds software versions 4.4.7 and earlier.
Real-world impact
An attacker could inject malicious SQL commands to read, modify, or delete sensitive information stored in the database, such as user credentials, listings, or financial data.
Why this severity
The CVSS score of 9.3 reflects that the attack can be performed over the network (AV:N), requires no authentication (PR:N), and has no user interaction (UI:N). The impact is high on confidentiality (C:H) with no impact on integrity or availability, and the attack complexity is low (AC:L).
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources