SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-5763

By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working.

MEDIUM 5.9EPSS 1.06%

Does this matter?

Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
1.06% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
oxid-esales/eshop
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.