5.4
CVSSv3

CVE-2023-26260

Published: 11/04/2023 Updated: 19/04/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

OXID eShop 6.2.x prior to 6.4.4 and 6.5.x prior to 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oxidforge oxid eshop