A SQL injection vulnerability has been identified in ShopEx ECShop versions up to 2.5.1. The flaw exists in the flow_update_cart function within /flow.php?step=update_cart, where the rec_id argument is not properly sanitized. An attacker can exploit this remotely without authentication to perform SQL injection attacks. The exploit has been publicly disclosed and is available for use. The vendor was notified prior to disclosure but did not respond. No patch or mitigation has been officially provided by the vendor. This poses a significant risk to e-commerce platforms running the affected version of ECShop.