Sceawere

Vulnerability Detail

CVE-2026-105226UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

osCommerce Remote Code Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
13h ago
Vendor
osCommerce
Product
osCommerce2
Attack Type
Code Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in osCommerce osCommerce2 up to 2.3.4.1. This vulnerability affects the function include of the file admin/newsletters.php of the component Newsletter Management. Performing a manipulation of the argument module results in code injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-10-05T05:17:03.087Z",
  "pubdate": "2026-10-05T05:17:03.087Z",
  "executiveSummary": "A remote code injection vulnerability exists in osCommerce 2.3.4.1 and earlier versions within the Newsletter Management component.\nThe vulnerability originates from improper validation of user-supplied input in the 'module' argument of the admin/newsletters.php file.\nSuccessful exploitation allows an unauthenticated or authenticated attacker to execute arbitrary code on the underlying server, potentially leading to a full system compromise.\nThis flaw is categorized as a critical security risk due to the potential for remote execution of malicious payloads, complete loss of data confidentiality, and server takeover.\nThe vulnerability is currently public, and active exploitation is possible, necessitating immediate attention to secure affected installations.",
  "technicalDetails": "The vulnerability is located in the Newsletter Management module, specifically within the admin/newsletters.php file of osCommerce 2.3.4.1 and earlier.\nThe root cause is the improper handling of the 'module' parameter passed to an 'include' function call. By failing to sanitize or whitelist the input provided to this parameter, the application becomes susceptible to file inclusion or direct code injection attacks.\nThe attack flow involves an adversary crafting a malicious request targeting the admin/newsletters.php file. By manipulating the 'module' argument, the attacker can force the PHP interpreter to include or process unintended files or arbitrary code embedded within the input. This effectively bypasses the application's intended logic for newsletter module loading.\nBecause the 'module' argument is processed server-side through a dynamic include mechanism, an attacker can influence the execution context. If the server is configured to allow inclusion of remote resources or if the attacker can influence the filesystem path, this leads to Remote Code Execution (RCE). Even in restricted environments, if the input can be controlled, it may permit the inclusion of local files containing attacker-supplied malicious code (Local File Inclusion leading to RCE).\nThe exploit does not require complex prerequisites other than network access to the administration interface of the vulnerable osCommerce installation. Once the malicious payload is delivered via the 'module' parameter, the server-side script executes the injected code with the privileges of the web server user (e.g., www-data).\nPost-exploitation impact includes unauthorized access to the application's database, manipulation of e-commerce records, exfiltration of customer sensitive information, and persistent backdoor installation on the host server. The vulnerability is highly critical as it provides a direct vector for total administrative control over the application environment."
}
CVE-2026-105226: osCommerce Remote Code Injection (MEDIUM Severity, CVSS: 4.7) | Sceawere