VYPR
Critical severity9.8NVD Advisory· Published Aug 1, 2016· Updated May 6, 2026

CVE-2016-4837

CVE-2016-4837

Description

SQL injection in EC-CUBE Coupon Plugin before 1.6 allows remote attackers to execute arbitrary SQL commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL injection in EC-CUBE Coupon Plugin before 1.6 allows remote attackers to execute arbitrary SQL commands.

Vulnerability

The Seed Coupon plugin for EC-CUBE, versions 1.5 and earlier, contains a SQL injection vulnerability (CWE-89) [1]. The flaw exists in unspecified vectors within the plugin, allowing direct injection of SQL queries through input parameters. The plugin is a coupon management component for the EC-CUBE e-commerce platform.

Exploitation

An attacker can exploit this vulnerability remotely over the network without requiring any authentication or user interaction [2]. The attack complexity is low, meaning an attacker can send a specially crafted HTTP request to the vulnerable plugin endpoint, injecting arbitrary SQL commands. No special privileges or access rights are needed.

Impact

Successful exploitation allows a remote attacker to obtain or alter information stored in the underlying database [1]. This can lead to disclosure of sensitive data such as customer information or order details, as well as modification or deletion of database contents. The CVSS v3 base score for this vulnerability is 9.8 (Critical), though the JPCERT/CC reports a base score of 6.5 (Medium) [2].

Mitigation

The vendor, Seed Inc., released a fixed version 1.6 of the Coupon Plugin [1]. Users should update to the latest version according to the developer's information. No workarounds are documented. The vulnerability was disclosed in July 2016 and the fix released shortly after.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.