Vulnerabilities
Vulnerable Software
Oxid-Esales:  >> Eshop  >> 6.1.0  Security Vulnerabilities
An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x. By using a specially crafted URL, users with administrative rights could unintentionally grant unauthorized users access to the admin panel via session fixation.
CVSS Score
8.8
EPSS Score
0.005
Published
2019-11-05
OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.
CVSS Score
9.8
EPSS Score
0.004
Published
2019-07-30


Contact Us

Shodan ® - All rights reserved