CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2019-25260

HIGH
8.2
CVSS Severity Score
EPSS Score0.0650%
EPSS Percentile26.90th
Published2026年2月3日
Last Modified2026年4月15日

Vulnerability Description

OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相關漏洞威脅