View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0007991 | OXID eShop (all versions) | 2. ----- eShop backend (admin) ----- | public | 2026-07-31 13:58 | 2026-07-31 13:58 |
| Reporter | Stefan_Werner | Assigned To | |||
| Priority | normal | Severity | major | Reproducibility | always |
| Status | new | Resolution | open | ||
| Product Version | 7.4.1 | ||||
| Summary | 0007991: SQL Injection via getRequestEscapedParameter() via Admin | ||||
| Description | getRequestEscapedParameter() doesnt escape parameters if its used in admin focus so some functions allow sql injections especially if used in combination with $database = \OxidEsales\Eshop\Core\DatabaseProvider::getDb(); Example: htdocs/vendor/oxid-esales/oxideshop-ee/Application/Controller/Admin/ArticleRightsBuyableAjax.php htdocs/vendor/oxid-esales/oxideshop-ee/Application/Controller/Admin/AttributeCategoryAjax.php and more | ||||
| Additional Information | Many versions, all editions and | ||||
| Tags | No tags attached. | ||||
| Theme | Not defined | ||||
| Browser | Not defined | ||||
| PHP Version | Not defined | ||||
| Database Version | Not defined | ||||