CVE-2019-25497: osCommerce 2.3.4.1 SQL Injection via currency Parameter
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the currency parameter. Attackers can send GET requests to shoppingcart.php with malicious currency values using boolean-based SQL injection payloads to extract sensitive database information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25497?
CVE-2019-25497 has a medium severity level, as it allows unauthenticated SQL injection attacks.
How do I fix CVE-2019-25497?
To fix CVE-2019-25497, update your osCommerce installation to the latest version that addresses this vulnerability.
Who is affected by CVE-2019-25497?
CVE-2019-25497 affects users of osCommerce version 2.3.4.1 specifically.
What kind of attack does CVE-2019-25497 enable?
CVE-2019-25497 enables attackers to perform SQL injection attacks through the currency parameter.
What impact does CVE-2019-25497 have on osCommerce sites?
CVE-2019-25497 can potentially allow attackers to manipulate database queries, which may lead to unauthorized data access.