Sceawere

Vulnerability Detail

CVE-2026-105225UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

osCommerce Remote Code Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
13h ago
Vendor
osCommerce
Product
osCommerce2
Attack Type
Code Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in osCommerce osCommerce2 up to 2.3.4.1. This affects the function include of the file includes/classes/payment.php of the component Payment Page. Such manipulation of the argument MODULE_PAYMENT_INSTALLED leads to code injection. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-05T05:17:02.900Z",
  "pubdate": "2026-10-05T05:17:02.900Z",
  "executiveSummary": "A critical code injection vulnerability exists in osCommerce versions up to 2.3.4.1, specifically within the payment module processing logic. This flaw allows an unauthenticated, remote attacker to execute arbitrary PHP code on the underlying server by manipulating the MODULE_PAYMENT_INSTALLED argument.\nThe vulnerability is categorized as a remote code injection flaw, potentially leading to full system compromise. Because osCommerce often operates with elevated web server privileges, a successful exploit grants the attacker the ability to read or modify sensitive databases, exfiltrate customer information, or deploy web shells for persistent unauthorized access.\nThe attack is characterized by its remote exploitability and the presence of public exploit scripts, significantly increasing the risk of active exploitation. No special authentication or administrative privileges are required to trigger the vulnerable code path. Organizations utilizing affected versions are at high risk, as the project has not provided a patch to remediate this specific injection vector.",
  "technicalDetails": "The vulnerability resides within the includes/classes/payment.php file of the osCommerce 2.3.4.1 component. The root cause is the improper handling of user-supplied input provided to the MODULE_PAYMENT_INSTALLED constant/variable, which is subsequently passed into a dynamic inclusion function. The application logic fails to sanitize or validate the input before using it to dynamically construct file paths or include external PHP scripts.\nWhen the payment module processing routine is triggered, the script processes the MODULE_PAYMENT_INSTALLED argument. If an attacker injects malicious input into this parameter, they can manipulate the execution flow of the 'include' statement. This allows the attacker to point the application toward a malicious file controlled by the attacker or exploit local file inclusion (LFI) techniques if the environment permits, effectively enabling remote code execution (RCE).\nThe attack flow begins with the attacker identifying the target's web-accessible entry point for the payment component. The attacker then crafts a malicious HTTP request that incorporates an arbitrary payload within the MODULE_PAYMENT_INSTALLED parameter. Upon receipt, the vulnerable 'include' function executes the payload within the context of the web server process. Because the server trusts this parameter during the payment initialization phase, it proceeds to compile and execute the malicious instructions contained within the injected input.\nThe impact of this vulnerability is severe. Upon successful execution, the attacker gains the ability to execute arbitrary PHP code, bypassing application-level security controls. Post-exploitation, the attacker can leverage this access to perform lateral movement within the network, dump the application's database containing user credentials and transaction records, or install backdoors to maintain long-term persistence on the host server. The vulnerability is network-exposed, requiring no pre-existing authentication, making it an ideal target for automated scanning and exploitation scripts currently circulating in the threat landscape."
}
CVE-2026-105225: osCommerce Remote Code Injection (MEDIUM Severity, CVSS: 4.3) | Sceawere