CVE-2018-5763

EUVD-2018-17532
An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Affected Products (NVD)
VendorProductVersion
oxid-esaleseshop
𝑥
< 5.3.7
oxid-esaleseshop
6.0.0
oxid-esaleseshop
6.0.0:rc1
oxid-esaleseshop
6.0.0:rc2
oxid-esaleseshop
6.0.0:rc3
𝑥
= Vulnerable software versions