CVE-2019-17062

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/11/2019
Last modified:
08/11/2019

Description

An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x. By using a specially crafted URL, users with administrative rights could unintentionally grant unauthorized users access to the admin panel via session fixation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oxid-esales:eshop:*:*:*:*:community:*:*:* 4.9.0 (including) 4.10.0 (including)
cpe:2.3:a:oxid-esales:eshop:*:*:*:*:professional:*:*:* 4.9.0 (including) 4.10.0 (including)
cpe:2.3:a:oxid-esales:eshop:*:*:*:*:enterprise:*:*:* 5.2.0 (including) 5.3.0 (including)
cpe:2.3:a:oxid-esales:eshop:*:*:*:*:community:*:*:* 6.0.0 (including) 6.0.6 (excluding)
cpe:2.3:a:oxid-esales:eshop:*:*:*:*:enterprise:*:*:* 6.0.0 (including) 6.0.6 (excluding)
cpe:2.3:a:oxid-esales:eshop:*:*:*:*:professional:*:*:* 6.0.0 (including) 6.0.6 (excluding)
cpe:2.3:a:oxid-esales:eshop:*:*:*:*:community:*:*:* 6.1.0 (including) 6.1.5 (excluding)
cpe:2.3:a:oxid-esales:eshop:*:*:*:*:enterprise:*:*:* 6.1.0 (including) 6.1.5 (excluding)
cpe:2.3:a:oxid-esales:eshop:*:*:*:*:professional:*:*:* 6.1.0 (including) 6.1.5 (excluding)


References to Advisories, Solutions, and Tools