CVE-2019-25260

HIGH

OXID eShop <6.3.4 - SQL Injection

Title source: llm
STIX 2.1

Description

OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.

Exploits (1)

exploitdb WORKING POC
by VulnSpy · textwebappsphp
https://www.exploit-db.com/exploits/48527

Scores

CVSS v3 8.2
EPSS 0.0002
EPSS Percentile 6.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
OXID-eSales/OXID eShop Versions 6.x (prior to 6.3.4)
Published Feb 03, 2026
Tracked Since Feb 18, 2026