Security bulletin: 2011-001

Released: 02/03/11

The following issue has been identified:


A possibility for SQL injection was found.


Resolved in OXID eShop version 4.4.6.


When using specially crafted data, it’s possible to make SQL injection from eShop frontend.
No exploits are known as of today.

Affected products, releases and platforms


  • OXID eShop Enterprise Edition
  • OXID eShop Professional Edition
  • OXID eShop Community Edition


  • Professional, Enterprise and Community Edition:,,,,,,, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, 4.1.6, 4.2.0, 4.3.0, 4.3.1, 4.3.2, 4.4.0, 4.4.1, 4.4.2, 4.4.3, 4.4.4 and 4.4.5.


  • Above releases are affected on all platforms.


The issue has been addressed in the following releases:

  • OXID eShop Professional Edition version 4.4.6
  • OXID eShop Enterprise Edition version 4.4.6
  • OXID eShop Community Edition version 4.4.6


The security issue has been reported by Thorsten Albrecht (

Stay up-to-date

To receive upcoming OXID Security Bulletins, please subscribe to the mailing lists or the Announcement forum

How to report security issues

Learn how to report security issues in the Security overview page.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published.