OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary dynamical user groups.
References
Link | Resource |
---|---|
https://oxidforge.org/en/security-bulletin-2014-003.html | Mitigation Vendor Advisory |
https://bugs.oxid-esales.com/view.php?id=5814 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2018-01-19 15:29
Updated : 2021-01-19 23:00
NVD link : CVE-2014-4919
Mitre link : CVE-2014-4919
JSON object : View
Products Affected
oxid-esales
- eshop
CWE
CWE-264
Permissions, Privileges, and Access Controls