Metrics
Affected Vendors & Products
Wed, 04 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oxid-esales
Oxid-esales eshop |
|
| Vendors & Products |
Oxid-esales
Oxid-esales eshop |
Tue, 03 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs. | |
| Title | OXID eShop 6.3.4 - 'sorting' SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-04T20:53:45.268Z
Reserved: 2025-12-24T14:27:12.479Z
Link: CVE-2019-25260
Updated: 2026-02-04T20:53:42.068Z
Status : Awaiting Analysis
Published: 2026-02-03T22:16:20.260
Modified: 2026-02-04T16:33:44.537
Link: CVE-2019-25260
No data.