CVE-2018-25114 is a critical remote code execution vulnerability in osCommerce Online Merchant version 2.3.4.1. This flaw allows an unauthenticated attacker to inject arbitrary PHP code into the configure.php file via an accessible installer directory, leading to full server-side compromise. With a CVSS score of 9.3 (CRITICAL), it presents a low-complexity attack vector with no user interaction required, enabling complete confidentiality, integrity, and availability impact. While not listed on CISA KEV, exploit modules are publicly available in Metasploit and Nuclei, indicating a high likelihood of exploitation and significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| OsCommerce | Online Merchant | 2.3.4.1CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.