---
id: CVE-2021-47763
title: >-
  Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api
  'sort' parameter that allows attackers to inject malicious database queries
summary: >-
  Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api
  'sort' parameter that allows attackers to inject malicious database queries.
  Attackers can manipulate the sort parameter to reveal table and column names
  by sendin…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-89
vendor: Aimeos
product: Aimeos Laravel ecommerce platform
affected:
  - laravel_ecommerce_platform Aimeos 2021.10 LTS
published: '2026-01-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:16:44.597'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-47763'
references:
  - url: 'https://aimeos.org'
    label: disclosure@vulncheck.com
  - url: 'https://aimeos.org/laravel-ecommerce-package'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/50538'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-01-15T16:48:32.540553Z'
epss: 0.00339
epssPercentile: 0.25252
ingestedAt: '2026-10-08T16:52:14.669Z'
---

## Overview

Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries. Attackers can manipulate the sort parameter to reveal table and column names by sending crafted GET requests to the jsonapi/review endpoint.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
