OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oxid-esales
Oxid-esales eshop |
|
| Vendors & Products |
Oxid-esales
Oxid-esales eshop |
Tue, 03 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs. | |
| Title | OXID eShop 6.3.4 - 'sorting' SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-03T22:01:36.661Z
Reserved: 2025-12-24T14:27:12.479Z
Link: CVE-2019-25260
No data.
Status : Received
Published: 2026-02-03T22:16:20.260
Modified: 2026-02-03T22:16:20.260
Link: CVE-2019-25260
No data.
OpenCVE Enrichment
Updated: 2026-02-04T12:06:04Z
Weaknesses