{"api_version":"1","generated_at":"2026-07-24T23:46:46+00:00","cve":"CVE-2018-14020","urls":{"html":"https://cve.report/CVE-2018-14020","api":"https://cve.report/api/cve/CVE-2018-14020.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-14020","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-14020"},"summary":{"title":"CVE-2018-14020","description":"An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eShop's checkout procedure properly. To do so, the attacker must change the delivery address to one that is not verified by the Paymorrow module.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-08-20 22:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://oxidforge.org/en/security-bulletin-2018-003.html","name":"https://oxidforge.org/en/security-bulletin-2018-003.html","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin 2018-003 • OXIDforge","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.oxid-esales.com/view.php?id=6801","name":"https://bugs.oxid-esales.com/view.php?id=6801","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"0006801: It is possible to bypass the check for delivery address changes during checkout process - OXID eShop bugtrack","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-14020","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-14020","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"14020","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"paymorrow","cpe5":"paymorrow","cpe6":"1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"oxid_eshop","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14020","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"paymorrow","cpe5":"paymorrow","cpe6":"1.0.2","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"oxid_eshop","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14020","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"paymorrow","cpe5":"paymorrow","cpe6":"2.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"oxid_eshop","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14020","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"paymorrow","cpe5":"paymorrow","cpe6":"1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"oxid_eshop","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14020","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"paymorrow","cpe5":"paymorrow","cpe6":"1.0.2","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"oxid_eshop","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14020","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"paymorrow","cpe5":"paymorrow","cpe6":"2.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"oxid_eshop","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-14020","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eShop's checkout procedure properly. To do so, the attacker must change the delivery address to one that is not verified by the Paymorrow module."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://bugs.oxid-esales.com/view.php?id=6801","refsource":"CONFIRM","url":"https://bugs.oxid-esales.com/view.php?id=6801"},{"name":"https://oxidforge.org/en/security-bulletin-2018-003.html","refsource":"CONFIRM","url":"https://oxidforge.org/en/security-bulletin-2018-003.html"}]}},"nvd":{"publishedDate":"2018-08-20 22:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:paymorrow:paymorrow:1.0.2:rc1:*:*:*:oxid_eshop:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:paymorrow:paymorrow:1.0.0:*:*:*:*:oxid_eshop:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:paymorrow:paymorrow:2.0.0:*:*:*:*:oxid_eshop:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"14020","Ordinal":"130683","Title":"CVE-2018-14020","CVE":"CVE-2018-14020","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"14020","Ordinal":"1","NoteData":"An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eShop's checkout procedure properly. To do so, the attacker must change the delivery address to one that is not verified by the Paymorrow module.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"14020","Ordinal":"2","NoteData":"2018-08-20","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"14020","Ordinal":"3","NoteData":"2018-08-20","Type":"Other","Title":"Modified"}]}}}