VDB
Sign up
HIGH7.5

GHSA-4c39-hj99-5h2r

OXID eShop user impersonation vulnerability

Quick fix

GHSA-4c39-hj99-5h2r — oxid-esales/oxideshop-ce: upgrade to the fixed version with the command below.

composer require oxid-esales/oxideshop-ce:^4.5.0

Details

The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication token.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/oxid-esales/oxideshop-ce
Introduced in: 0Fixed in: 4.5.0
Fixcomposer require oxid-esales/oxideshop-ce:^4.5.0

References