Vendorsoxid-esaleseshop4.10.6
Vulnerabilities

oxid-esales OXID eSHOP 4.10.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2018-20715
The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.php.
Published 2019-01-15 · Modified
9.8EPSS 0.011