osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the currency parameter. Attackers can send GET requests to shopping_cart.php with malicious currency values using boolean-based SQL injection payloads to extract sensitive database information.
{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.3.4.1"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:oscommerce:oscommerce:*:*:*:*:*:*:*:*"
}