OXID eShop user impersonation vulnerability
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Dec 16, 2023
Description
Published by the National Vulnerability Database
Jan 19, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 31, 2023
Last updated
Dec 16, 2023
The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication token.
References