CVE-2019-25260 | OXID-eSales OXID eShop up to 6.3.3 sorting sql injection (Exploit 48527 / EDB-48527)
A vulnerability was found in OXID-eSales OXID eShop up to 6.3.3. It has been classified as critical. Affected is an unknown function. This manipulation of the argument sorting causes sql injection.
This vulnerability is tracked as CVE-2019-25260. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.