OXID eShop 6.3.4 - 'sorting' SQL Injection
Vulnerability Description
OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25260
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- VulnSpy
References
- https://www.exploit-db.com/exploits/48527
- https://www.oxid-esales.com/
- https://github.com/OXID-eSales/oxideshop_ce
- https://web.archive.org/web/20201020223434/https://www.vulnspy.com/en-oxid-eshop-6.x-sqli-to-rce/
- https://web.archive.org/web/20190731211638/https://blog.ripstech.com/2019/oxid-esales-shop-software/
- https://bugs.oxid-esales.com/view.php?id=7002
- https://www.vulncheck.com/advisories/oxid-eshop-sorting-sql-injection
Affected Vendor
OXID-eSales
View all reports →