Impact
A flaw was discovered in osCommerce osCommerce2, affecting versions up to 2.3.4.1, where the admin/newsletters.php module include uses the module argument without proper validation. An attacker can manipulate this parameter to include arbitrary code, effectively allowing them to inject and execute arbitrary PHP code on the server. The description specifies that code injection results from this misuse and that the exploit is available to the public, indicating that successful exploitation would give the attacker full control of the web application environment.
Affected Systems
The vulnerability applies to the osCommerce osCommerce2 product, specifically the Newsletter Management component used in the admin/newsletters.php file. All installations running version 2.3.4.1 or earlier are potentially impacted until a patch or new release addresses the unvalidated include.
Risk and Exploitability
The CVSS score of 5.1 reflects a moderate severity vulnerability. The EPSS score is not available, so the current likelihood of exploitation cannot be measured, although the exploit is publicly released. KEV lists the vulnerability as not included. The issue falls under CWE-74 and CWE-94, both describing improper handling of include arguments and dynamic code generation. The attack vector is remote, achievable by sending crafted requests to the module parameter of newsletters.php.
OpenCVE Enrichment