Home Security OXID eShop Vulnerabilities Could Allow Unauthenticated Remote Takeover

OXID eShop Vulnerabilities Could Allow Unauthenticated Remote Takeover

by

The eCommerce platform OXID has recently addressed some serious security flaws. These OXID eShop vulnerabilities could allow an attacker for remote takeover upon an exploit.

OXID eShop Vulnerabilities

Reportedly, researchers from RIPS have spotted multiple security flaws in the OXID eCommerce platform. As revealed, the flaws could allow remote website hacking upon exploiting by a potential attacker.

Elaborating on their findings regarding the OXID eShop vulnerabilities in their blog post, the researchers stated that they discovered two different vulnerabilities in the platform.

The researchers identified one of these vulnerabilities as a SQL injection flaw. An unauthenticated attacker could simply exploit the flaw with a specially crafted URL. This could allow the attacker to create a new admin account gaining full control of the website.

The researchers have demonstrated the exploit for this vulnerability in the following video.

In addition team RIPS also spotted another vulnerability in the admin panel of the platform. specifically, they found a PHP objection vulnerability in the import section that could induce RCE attacks. They have also shared a video as the PoC for the exploit.

OXID Patched The Flaws

Upon receiving the report regarding the flaw from researchers, OXID worked out to create a fix. They have acknowledged the vulnerability having CVE identifier CVE-2019-13026 in their security bulletin. According to the vulnerability description,

OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.

The vendors have rolled-out the fix with version OXID eShop v6.0.5 and v6.1.4 (Enterprise Edition, Community Edition, and Professional Edition).

The vendors confirmed there were no reports of exploits of the SQL injection flaw in the wild. However, they haven’t spoken on  the other vulnerability in the patched version.

Users of OXID eShop must ensure upgrading to the patched version to remain secure.

Let us know your thoughts in the comments.

The following two tabs change content below.

Avatar
Abeerah has been a passionate blogger for several years with a particular interest towards science and technology. She is crazy to know everything about the latest tech developments. Knowing and writing about cybersecurity, hacking, and spying has always enchanted her. When she is not writing, what else can be a better pastime than web surfing and staying updated about the tech world! Reach out to me at: [email protected]
Avatar

Source link

Related Articles

Leave a Comment

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More