A vulnerability has been found in highwarden Super Store Finder up to 3.8. Affected is an unknown function of the file /products/superstorefinder/index.php. The manipulation of the argument lat/lng leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 3.9 is able to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Project Subscriptions

Vendors Products
Highwarden Subscribe
Super Store Finder Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 11 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in highwarden Super Store Finder up to 3.8. Affected is an unknown function of the file /products/superstorefinder/index.php. The manipulation of the argument lat/lng leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 3.9 is able to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title highwarden Super Store Finder index.php sql injection
First Time appeared Highwarden
Highwarden super Store Finder
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:highwarden:super_store_finder:*:*:*:*:*:*:*:*
Vendors & Products Highwarden
Highwarden super Store Finder
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-11T06:30:14.152Z

Reserved: 2026-10-10T13:28:55.151Z

Link: CVE-2026-108541

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:23.700

Modified: 2026-10-11T07:17:23.700

Link: CVE-2026-108541

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T09:00:14Z

Weaknesses