What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mystyleplatform MyStyle Custom Product Designer mystyle-custom-product-designer allows Blind SQL Injection.This issue affects MyStyle Custom Product Designer: from n/a through <= 3.21.1.
Explanation of Vulnerability in Simple Terms
02Summary
MyStyle Custom Product Designer versions up to 3.21.1 contain a SQL injection vulnerability in unauthenticated requests. An attacker can query the database directly to extract sensitive data, including user information and site configuration. The vulnerability requires no authentication or user interaction, making it trivial to exploit remotely.
What an attacker can do
03Attacker Capabilities
Extract sensitive data from the site database, including user credentials and configuration details.
Potential impact on your site
04Site Impact
User data and site configuration exposed; attackers can read password hashes, email addresses, and other stored information.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
June 9, 2025
CVE published
May 12, 2026
Record updated