OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oxid-esales
Oxid-esales eshop |
|
| Vendors & Products |
Oxid-esales
Oxid-esales eshop |
Tue, 03 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs. | |
| Title | OXID eShop 6.3.4 - 'sorting' SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-03T22:01:36.661Z
Updated: 2026-02-03T22:01:36.661Z
Reserved: 2025-12-24T14:27:12.479Z
Link: CVE-2019-25260
No data.
Status : Awaiting Analysis
Published: 2026-02-03T22:16:20.260
Modified: 2026-02-04T16:33:44.537
Link: CVE-2019-25260
No data.