CVE-2018-20715
15.01.2019, 16:29
The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.php.
Vendor | Product | Version |
---|---|---|
oxid-esales | eshop | 4.10.6 |
𝑥
= Vulnerable software versions