Intel

AIKIDO-2026-10276

coreshop/core-shop is vulnerable to Generation of Error Message Containing Sensitive Information

Generation of Error Message Containing Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 2, 2026

19

Low Risk

This Affects:

PHPcoreshop/core-shop
2.0.0 - 4.1.9
Fixed in 4.1.10
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to sensitive information exposure through error responses in the OrderInvoiceController and OrderShipmentController. In the event of a server error, detailed exception messages and full stack traces were previously returned directly to clients, potentially revealing internal implementation details such as class names, file paths, or control flow. This can aid attackers in reconnoitering the application and crafting further attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

coreshop/core-shop is vulnerable to Generation of Error Message Containing Sensitive Information in versions 2.0.0 - 4.1.9.

How to fix this

Upgrade the coreshop/core-shop library to a patch version.