Intel

AIKIDO-2026-10149

spryker/quote-request is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere

Exposure of Sensitive System Information to an Unauthorized Control Sphere Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 10, 2026

30

Low Risk

This Affects:

PHPspryker/quote-request
0.1.0 - 2.7.0
Fixed in 2.8.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package persisted quote request versions containing sensitive customer data, including passwords, in the database. An attacker who gains unauthorized read access to the database (via SQL injection, misconfigured backups, or compromised credentials) could extract stored credentials and reuse them for account takeover or lateral movement. This exposure increases the blast radius of a single breach by turning passive data access into credential compromise.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spryker/quote-request is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 0.1.0 - 2.7.0.

How to fix this

Upgrade the spryker/quote-request library to the patch version.