OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs. | |
| Title | OXID eShop 6.3.4 - 'sorting' SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-03T22:01:36.661Z
Reserved: 2025-12-24T14:27:12.479Z
Link: CVE-2019-25260
No data.
Status : Received
Published: 2026-02-03T22:16:20.260
Modified: 2026-02-03T22:16:20.260
Link: CVE-2019-25260
No data.
OpenCVE Enrichment
No data.