Infor Storefront B2B SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Infor Storefront B2B version 1.0. This vulnerability allows attackers to manipulate database queries by injecting malicious SQL code into the 'usr_name' parameter during login requests. Exploitation of this vulnerability could lead to unauthorized extraction or modification of database information.

Impact

Exploitation of this vulnerability allows for SQL injection, enabling attackers to interfere with the application's database queries. This could result in unauthorized data access, data manipulation, or potentially executing administrative operations on the database.

Reproduction

The vulnerability can be reproduced by sending a login request to the 'login.do' endpoint of the 'storefrontB2BWEB' application. Injected SQL code can be appended to the 'usr_name' parameter, which will be processed by the application's database, allowing for SQL injection exploitation. Alternatively, the vulnerability can be exploited through the 'cart.do' endpoint by injecting SQL code into the 'itm_id' parameter.

Added: Jan 30, 2026, 11:32 PM
Updated: Jan 30, 2026, 11:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
8.7
remediation
0.0
relevance
2.4
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.