What is CVE-2026-18592?
A SQL injection vulnerability has been discovered in the EmailController function of osCommerce 4.14.63493, affecting the Email Template Configuration component. The flaw allows manipulation of the email_templates_key argument, potentially leading to remote code execution. Users are advised to immediately apply any available patches and contact their administrators.
Azərbaycanca: osCommerce 4.14.63493 platformasında EmailController funksiyasında SQL injection zəifliyi aşkar edilib. Bu boşluq email_templates_key arqumentinin manipulyasiyası nəticəsində yaranır və uzaqdan kod icrasına səbəb ola bilər. İstifadəçilərə dərhal administratorlarla əlaqə saxlayıb yamaq tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ1
What vulnerability has been found in the EmailController of osCommerce 4.14.63493 and how is it exploited?
A SQL injection vulnerability has been discovered in the EmailController function of osCommerce 4.14.63493. This flaw is caused by the manipulation of the email_templates_key argument and can lead to remote code execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.