VulnerabilityModified
CVE-2018-14020
An attacker can bypass delivery-address change detection if the payment module doesn't use eShop's checkout procedure properly.
MEDIUM 5.3EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eShop's checkout procedure properly. To do so, the attacker must change the delivery address to one that is not verified by the Paymorrow module.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- paymorrow/paymorrow
- Source
- cve@mitre.org
References
- https://bugs.oxid-esales.com/view.php?id=6801Vendor Advisory
- https://oxidforge.org/en/security-bulletin-2018-003.htmlVendor Advisory
- https://bugs.oxid-esales.com/view.php?id=6801Vendor Advisory
- https://oxidforge.org/en/security-bulletin-2018-003.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.