7.5

CVE-2017-14993

OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition before 6.0.0 RC3 (development), 5.2.x before 5.2.11 (legacy), and 5.3.x before 5.3.6 (maintenance), and Professional Edition before 6.0.0 RC3 (development), 4.9.x before 4.9.11 (legacy) and 4.10.x before 4.10.6 (maintenance) allow remote attackers to crawl specially crafted URLs (aka "forced browsing") in order to overflow the database of the shop and consequently make it stop working. Prerequisite: the shop allows rendering empty categories to the storefront via an admin option.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oxid-esales ≫ Eshop SwEdition community Version >= 4.9.0 < 4.9.11
Oxid-esales ≫ Eshop SwEdition professional Version >= 4.9.0 < 4.9.11
Oxid-esales ≫ Eshop SwEdition community Version >= 4.10.0 < 4.10.6
Oxid-esales ≫ Eshop SwEdition professional Version >= 4.10.0 < 4.10.6
Oxid-esales ≫ Eshop SwEdition enterprise Version >= 5.2.0 < 5.2.11
Oxid-esales ≫ Eshop SwEdition enterprise Version >= 5.3.0 < 5.3.6
Oxid-esales ≫ Eshop Version 6.0.0 Update rc1 SwEdition community
Oxid-esales ≫ Eshop Version 6.0.0 Update rc1 SwEdition enterprise
Oxid-esales ≫ Eshop Version 6.0.0 Update rc1 SwEdition professional
Oxid-esales ≫ Eshop Version 6.0.0 Update rc2 SwEdition community
Oxid-esales ≫ Eshop Version 6.0.0 Update rc2 SwEdition enterprise
Oxid-esales ≫ Eshop Version 6.0.0 Update rc2 SwEdition professional
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.652
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

https://bugs.oxid-esales.com/view.php?id=6678
Vendor Advisory
https://oxidforge.org/en/security-bulletin-2017-002.html
Patch
Vendor Advisory