CVE-2026-108828 | Zen Cart 2.2.2 Admin Panel admin/configuration.php eval gID sql injection (GHSA-233f-2p5c-vfgw)

SecurityVulns

A vulnerability was found in Zen Cart 2.2.2. It has been classified as problematic. Affected by this vulnerability is the function eval of the file admin/configuration.php of the component Admin Panel. The manipulation of the argument gID leads to sql injection.

This vulnerability is listed as CVE-2026-108828. The attack may be initiated remotely. In addition, an exploit is available.

The vendor explains: “`set_function`/`use_function` are not editable through any normal admin UI (only at plugin-install time via SQL, or via direct database access)”.VulDB Recent EntriesRead More