5.3
CVSSv3

CVE-2023-38330

Published: 02/08/2023 Updated: 08/08/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

OXID eShop Enterprise Edition 6.5.0 – 6.5.2 prior to 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack.

Vulnerable Product Search on Vulmon Subscribe to Product

oxid-esales eshop