Impact
This flaw allows untrusted users to inject arbitrary SQL through the rec_id parameter used by the flow_update_cart function in the /flow.php?step=update_cart endpoint. The injection can lead to unauthorized data disclosure, credential theft, or data manipulation.
Affected Systems
The issue exists in ShopEx ECShop versions up to and including 2.5.1. Attackers target the flow_update_cart function within the /flow.php file; no other products or versions are known to be affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate to high severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified from the current data, and the vulnerability is not listed in the CISA KEV catalog. The description states that the attack can be initiated remotely, implying that any party that can reach the application can exploit the rec_id parameter by sending a crafted HTTP request. The lack of a publicly available fix and the vendor’s unresponsiveness raise the risk that the flaw may remain in use for an extended period.
OpenCVE Enrichment