Ashopsoftware Vulnerabilities and Affected Products
Vulnerabilities associated with Ashop Shopping Cart Software.
Products
Clear product- Ashop Shopping Cart Software2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-25507HIGH | Ashop Shopping Cart Software Lastest SQL Injection via index.phpAshop Shopping Cart Software contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'shop' parameter. Attackers can send GET requests to index.php with malicious 'shop' values using UNION-based SQL injection to extract sensitive database information. CWE-89Mar 4, 2026 | CVSS8.8v4.0 | EPSS0.237% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25391HIGH | Ashop Shopping Cart Software Lastest Latest SQL Injection via bannedcustomers.phpAshop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the blacklistitemid parameter. Attackers can send POST requests to the admin/bannedcustomers.php endpoint with crafted SQL payloads using SLEEP functions to extract sensitive database information. CWE-89Feb 22, 2026 | CVSS8.8v4.0 | EPSS0.263% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |