CVE-2018-14020
Summary
| CVE | CVE-2018-14020 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-20 22:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eShop's checkout procedure properly. To do so, the attacker must change the delivery address to one that is not verified by the Paymorrow module. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Paymorrow | Paymorrow | 1.0.0 | All | All | All |
| Application | Paymorrow | Paymorrow | 1.0.2 | rc1 | All | All |
| Application | Paymorrow | Paymorrow | 2.0.0 | All | All | All |
| Application | Paymorrow | Paymorrow | 1.0.0 | All | All | All |
| Application | Paymorrow | Paymorrow | 1.0.2 | rc1 | All | All |
| Application | Paymorrow | Paymorrow | 2.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin 2018-003 • OXIDforge | CONFIRM | oxidforge.org | Vendor Advisory |
| 0006801: It is possible to bypass the check for delivery address changes during checkout process - OXID eShop bugtrack | CONFIRM | bugs.oxid-esales.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.