CVE-2019-25260 - CVE House
Back to Database
Status published High CVE-2019-25260

OXID eShop 6.3.4 - 'sorting' SQL Injection

Vulnerability Description

OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25260

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • VulnSpy

Affected Vendor

OXID-eSales

View all reports →

Affected Software

OXID eShop
Vulnerable Versions:
Versions 6.x (prior to 6.3.4)

Timeline

Official Publish: February 3rd, 2026
Last Modified: July 15th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Weaknesses (CWE)