← Back

CVE-2019-13026

nvd nist
Published: Jul 30, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.

Affected (2)

Products: Oxid Esales: Eshop
1 product
Eshop
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Oxid Esales
From 6.0.0 to 6.0.5
From 6.1.0 to 6.1.4

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.