CVE-2014-4919
Summary
| CVE | CVE-2014-4919 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-19 15:29:00 UTC |
| Updated | 2021-01-19 23:00:00 UTC |
| Description | OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary dynamical user groups. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oxid-esales | Eshop | All | All | All | All |
| Application | Oxid-esales | Eshop | All | All | All | All |
| Application | Oxid-esales | Eshop | All | All | All | All |
| Application | Oxid-esales | Eshop | All | All | All | All |
| Application | Oxid-esales | Eshop | All | All | All | All |
| Application | Oxid-esales | Eshop | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security bulletin: 2014-003 › OXIDforge | CONFIRM | oxidforge.org | Mitigation, Vendor Advisory |
| 0005814: Possible to assign to any user group without admin confirmation - OXID eShop bugtrack | CONFIRM | bugs.oxid-esales.com | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.