CVE-2026-82922: ShopEx ECShop flow.php flow_update_cart sql injection
A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flowupdatecart of the file /flow.php?step=updatecart. The manipulation of the argument recid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
ShopEx ECShop versions up to 2.5.1 are affected, specifically the cart-update functionality reached through /flow.php?step=update_cart.
Does exploitation require authentication or user interaction?
No. The supplied severity vector indicates network reachability, low attack complexity, no privileges required, and no user interaction.
What input should defenders focus on when investigating exposure?
Investigate requests to /flow.php?step=update_cart that manipulate the rec_id argument, as this parameter is identified as the SQL injection point.
How urgent is mitigation?
The issue is rated high severity and public exploit disclosure has been reported. The vendor reportedly did not respond to the disclosure, so organizations should not assume a vendor fix is available.