Back

HIGH

OXID eShop 6.3.4 - 'sorting' SQL Injection

Published Feb 3, 2026

Description

OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Feb 3, 2026
Updated Jul 15, 2026
Reserved Dec 24, 2025
CISA Vulnrichment
Updated Feb 4, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Feb 3, 2026
Updated Jul 15, 2026
Exploited since n/a
EUVD-2019-19383