CVE-2019-25495 | osCommerce 2.3.4.1 product_reviews_write.php reviews_id sql injection (Exploit 46330 / EDB-46330)
A vulnerability was found in osCommerce 2.3.4.1. It has been declared as critical. This vulnerability affects unknown code of the file product_reviews_write.php. The manipulation of the argument reviews_id results in sql injection.
This vulnerability is identified as CVE-2019-25495. The attack can be executed remotely. Additionally, an exploit exists.