CVE-2026-23959 | CoreShop up to 4.1.8 Admin Panel CustomerTransformerController sql injection (GHSA-fqcv-8859-86x2)
A vulnerability marked as problematic has been reported in CoreShop up to 4.1.8. This issue affects the function CustomerTransformerController of the component Admin Panel. The manipulation leads to sql injection hibernate.
This vulnerability is traded as CVE-2026-23959. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.