CVE-2019-25260

high

Description

OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.

References

https://www.vulncheck.com/advisories/oxid-eshop-sorting-sql-injection

https://www.oxid-esales.com/

https://www.exploit-db.com/exploits/48527

https://web.archive.org/web/20201020223434/https://www.vulnspy.com/en-oxid-eshop-6.x-sqli-to-rce/

https://web.archive.org/web/20190731211638/https://blog.ripstech.com/2019/oxid-esales-shop-software/

https://github.com/OXID-eSales/oxideshop_ce

https://bugs.oxid-esales.com/view.php?id=7002

Details

Source: Mitre, NVD

Published: 2026-02-03

Updated: 2026-02-04

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:P/A:N

Severity: High

CVSS v3

Base Score: 8.2

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Severity: High

CVSS v4

Base Score: 8.8

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00043