OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary dynamical user groups.
References
Link | Resource |
---|---|
https://bugs.oxid-esales.com/view.php?id=5814 | Issue Tracking Vendor Advisory |
https://oxidforge.org/en/security-bulletin-2014-003.html | Mitigation Vendor Advisory |
https://bugs.oxid-esales.com/view.php?id=5814 | Issue Tracking Vendor Advisory |
https://oxidforge.org/en/security-bulletin-2014-003.html | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 02:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.oxid-esales.com/view.php?id=5814 - Issue Tracking, Vendor Advisory | |
References | () https://oxidforge.org/en/security-bulletin-2014-003.html - Mitigation, Vendor Advisory |
Information
Published : 2018-01-19 15:29
Updated : 2024-11-21 02:11
NVD link : CVE-2014-4919
Mitre link : CVE-2014-4919
CVE.ORG link : CVE-2014-4919
JSON object : View
Products Affected
oxid-esales
- eshop
CWE
CWE-264
Permissions, Privileges, and Access Controls