CVE-2018-14020
Last modified
CVE-2018-14020 is a vulnerability of currently unknown severity. An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eShop's checkout procedure properly. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eShop's checkout procedure properly. To do so, the attacker must change the delivery address to one that is not verified by the Paymorrow module.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Paymorrow | Paymorrow | 1.0.0 | — |
| Paymorrow | Paymorrow | 1.0.2 | Rc1 |
| Paymorrow | Paymorrow | 2.0.0 | — |
References
- https://bugs.oxid-esales.com/view.php?id=6801Vendor Advisory
- https://oxidforge.org/en/security-bulletin-2018-003.htmlVendor Advisory
- https://bugs.oxid-esales.com/view.php?id=6801Vendor Advisory
- https://oxidforge.org/en/security-bulletin-2018-003.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14020?
How severe is CVE-2018-14020?
How do I fix CVE-2018-14020?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-14012WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to …
- CVE-2018-14013Synacor Zimbra Collaboration Suite Collaboration before 8.8.…
- CVE-2018-14014In waimai Super Cms 20150505, there is a CSRF vulnerability …
- CVE-2018-14015The sdb_set_internal function in sdb.c in radare2 2.7.0 allo…5.5
- CVE-2018-14016The r_bin_mdmp_init_directory_entry function in mdmp.c in ra…5.5
- CVE-2018-14017The r_bin_java_annotation_new function in shlr/java/class.c …5.5
- CVE-2018-14023Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.…
- CVE-2018-14027Digisol Wireless Wifi Home Router HR-3300 allows XSS via the…
- CVE-2018-14028In WordPress 4.9.7, plugins uploaded via the admin area are …
- CVE-2018-14029CSRF vulnerability in admin/user/edit in Creatiwity wityCMS …
- CVE-2018-1403IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 …5.4
- CVE-2018-14031An issue was discovered in the HDF HDF5 1.8.20 library. Ther…
Are you affected by CVE-2018-14020?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
