CVE Vulnerabilities

CVE-2014-4919

Published: Jan 19, 2018 | Modified: Jan 19, 2021
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary dynamical user groups.

Affected Software

Name Vendor Start Version End Version
Eshop Oxid-esales * 4.7.13 (excluding)
Eshop Oxid-esales 4.8.0 (including) 4.8.7 (excluding)

References