PT-2026-35349 · Unknown · Likeadmin-Likeshop

Z0Ng

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7083

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions likeadmin-likeshop likeadmin php versions prior to 1.9.7
Description A remote SQL injection exists in the dataTable Admin API component. The issue is located in the queryResult() function within the serverappadminapiliststoolsDataTableLists.php file, allowing for remote manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the queryResult() function in the serverappadminapiliststoolsDataTableLists.php file to minimize the risk of exploitation.

Exploit

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7083

Affected Products

Likeadmin-Likeshop