CVE-2026-82922: ShopEx ECShop flow.php flow_update_cart sql injection

Published Aug 31, 2026
·
Updated

A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flowupdatecart of the file /flow.php?step=updatecart. The manipulation of the argument recid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
shopex ecshop<=2.5.1

Event History

Aug 31, 2026
CVE Published
via MITRE·09:30 PM
Data Sourced
via MITRE·09:30 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

ShopEx ECShop versions up to 2.5.1 are affected, specifically the cart-update functionality reached through /flow.php?step=update_cart.

2

Does exploitation require authentication or user interaction?

No. The supplied severity vector indicates network reachability, low attack complexity, no privileges required, and no user interaction.

3

What input should defenders focus on when investigating exposure?

Investigate requests to /flow.php?step=update_cart that manipulate the rec_id argument, as this parameter is identified as the SQL injection point.

4

How urgent is mitigation?

The issue is rated high severity and public exploit disclosure has been reported. The vendor reportedly did not respond to the disclosure, so organizations should not assume a vendor fix is available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203