CVE-2026-82922 | ShopEx ECShop up to 2.5.1 flow.php?step=update_cart flow_update_cart rec_id sql injection
A vulnerability identified as critical has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argument rec_id leads to sql injection.
This vulnerability is documented as CVE-2026-82922. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More