7.5
CVE-2017-14993
- EPSS 1.2%
- Veröffentlicht 20.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:13:54
- Erkennungen
OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition before 6.0.0 RC3 (development), 5.2.x before 5.2.11 (legacy), and 5.3.x before 5.3.6 (maintenance), and Professional Edition before 6.0.0 RC3 (development), 4.9.x before 4.9.11 (legacy) and 4.10.x before 4.10.6 (maintenance) allow remote attackers to crawl specially crafted URLs (aka "forced browsing") in order to overflow the database of the shop and consequently make it stop working. Prerequisite: the shop allows rendering empty categories to the storefront via an admin option.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oxid-esales ≫ Eshop SwEdition community Version >= 4.9.0 < 4.9.11
Oxid-esales ≫ Eshop SwEdition professional Version >= 4.9.0 < 4.9.11
Oxid-esales ≫ Eshop SwEdition community Version >= 4.10.0 < 4.10.6
Oxid-esales ≫ Eshop SwEdition professional Version >= 4.10.0 < 4.10.6
Oxid-esales ≫ Eshop SwEdition enterprise Version >= 5.2.0 < 5.2.11
Oxid-esales ≫ Eshop SwEdition enterprise Version >= 5.3.0 < 5.3.6
Oxid-esales ≫ Eshop Version 6.0.0 Update rc1 SwEdition community
Oxid-esales ≫ Eshop Version 6.0.0 Update rc1 SwEdition enterprise
Oxid-esales ≫ Eshop Version 6.0.0 Update rc1 SwEdition professional
Oxid-esales ≫ Eshop Version 6.0.0 Update rc2 SwEdition community
Oxid-esales ≫ Eshop Version 6.0.0 Update rc2 SwEdition enterprise
Oxid-esales ≫ Eshop Version 6.0.0 Update rc2 SwEdition professional
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.2% | 0.652 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-425 Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
https://bugs.oxid-esales.com/view.php?id=6678
https://oxidforge.org/en/security-bulletin-2017-002.html