Vulnerabilities (CVE)

Filtered by vendor Oxid-esales Subscribe
Filtered by product Eshop
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38330 1 Oxid-esales 1 Eshop 2023-08-08 N/A 5.3 MEDIUM
OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack.
CVE-2014-4919 1 Oxid-esales 1 Eshop 2021-01-19 5.8 MEDIUM 5.4 MEDIUM
OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary dynamical user groups.
CVE-2018-5763 1 Oxid-esales 1 Eshop 2018-03-20 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used.