OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary dynamical user groups.
References
Link | Resource |
---|---|
https://bugs.oxid-esales.com/view.php?id=5814 | Issue Tracking Vendor Advisory |
https://oxidforge.org/en/security-bulletin-2014-003.html | Mitigation Vendor Advisory |
https://bugs.oxid-esales.com/view.php?id=5814 | Issue Tracking Vendor Advisory |
https://oxidforge.org/en/security-bulletin-2014-003.html | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2018-01-19 15:29
Updated : 2024-11-21 02:11
NVD link : CVE-2014-4919
Mitre link : CVE-2014-4919
CVE.ORG link : CVE-2014-4919
JSON object : View
Products Affected
oxid-esales
- eshop
CWE
CWE-264
Permissions, Privileges, and Access Controls