Vulnerability Description
OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oxid-Esales | Eshop | >= 6.0.0, < 6.0.5 |
Related Weaknesses (CWE)
References
- https://oxidforge.org/en/security-bulletin-2019-001.htmlVendor Advisory
- https://oxidforge.org/en/security-bulletin-2019-001.htmlVendor Advisory
FAQ
What is CVE-2019-13026?
CVE-2019-13026 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the data...
How severe is CVE-2019-13026?
CVE-2019-13026 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-13026?
Check the references section above for vendor advisories and patch information. Affected products include: Oxid-Esales Eshop.