Unrated severityNVD Advisory· Published Jul 4, 2026· Updated Jul 7, 2026
CodeAstro Ecommerce Website my_account.php sql injection
CVE-2026-14639
Description
A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected products
1- Range: = 1.0
Patches
Vulnerability mechanics
References
6- github.com/Laichen-0/CVE/issues/1mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-14639mitrethird-party-advisory
- vuldb.com/submit/845974mitrethird-party-advisory
- codeastro.commitreproduct
- vuldb.com/vuln/376155mitrevdb-entrytechnical-description
- vuldb.com/vuln/376155/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.