CVE Vulnerabilities

CVE-2018-14020

Published: Aug 20, 2018 | Modified: Oct 03, 2019
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesnt use eShops checkout procedure properly. To do so, the attacker must change the delivery address to one that is not verified by the Paymorrow module.

Affected Software

Name Vendor Start Version End Version
Paymorrow Paymorrow 1.0.0 1.0.0
Paymorrow Paymorrow 1.0.2 1.0.2
Paymorrow Paymorrow 2.0.0 2.0.0

References