OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary dynamical user groups.
References
Link | Resource |
---|---|
https://oxidforge.org/en/security-bulletin-2014-003.html | Mitigation Vendor Advisory |
https://bugs.oxid-esales.com/view.php?id=5814 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2018-01-19 07:29
Updated : 2021-01-19 15:00
NVD link : CVE-2014-4919
Mitre link : CVE-2014-4919
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
oxid-esales
- eshop