« Volver al listado

CVE-2017-12415

Estado: ModificadaAlta (7.5)—

OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development), 5.2.x before 5.2.10 (legacy), and 5.3.x before 5.3.5 (maintenance), and Professional Edition before 6.0.0 RC2 (development), 4.9.x before 4.9.10 (legacy) and 4.10.x before 4.10.5 (maintenance) allow remote attackers to hijack the cart session of a client via Cross-Site Request Forgery (CSRF) if the following pre-conditions are met: (1) the attacker knows which shop is presently used by the client, (2) the attacker knows the exact time when the customer will add product items to the cart, (3) the attacker knows which product items are already in the cart (has to know their article IDs), and (4) the attacker would be able to trick user into clicking a button (submit form) of an e-mail or remote site within the period of visiting the shop and placing an order.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-12415",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-02-20T23:29:00.247",
  "references": [
    {
      "url": "https://bugs.oxid-esales.com/view.php?id=6674",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://oxidforge.org/en/security-bulletin-2017-001.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.oxid-esales.com/view.php?id=6674",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oxidforge.org/en/security-bulletin-2017-001.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development), 5.2.x before 5.2.10 (legacy), and 5.3.x before 5.3.5 (maintenance), and Professional Edition before 6.0.0 RC2 (development), 4.9.x before 4.9.10 (legacy) and 4.10.x before 4.10.5 (maintenance) allow remote attackers to hijack the cart session of a client via Cross-Site Request Forgery (CSRF) if the following pre-conditions are met: (1) the attacker knows which shop is presently used by the client, (2) the attacker knows the exact time when the customer will add product items to the cart, (3) the attacker knows which product items are already in the cart (has to know their article IDs), and (4) the attacker would be able to trick user into clicking a button (submit form) of an e-mail or remote site within the period of visiting the shop and placing an order."
    },
    {
      "lang": "es",
      "value": "OXID eShop Community Edition en versiones anteriores a la 6.0.0 RC2 (development), 4.10.x anteriores a la 4.10.5 (maintenance) y versiones 4.9.x anteriores a la 4.9.10 (legacy); Enterprise Edition en versiones anteriores a la 6.0.0 RC2 (development), versiones 5.2.x anteriores a la 5.2.10 (legacy) y versiones 5.3.x anteriores a la 5.3.5 (maintenance) y Professional Edition en versiones anteriores a la 6.0.0 RC2 (development), versiones 4.9.x anteriores a la 4.9.10 (legacy) y 4.10.x anteriores a la 4.10.5 (maintenance) permiten que atacantes remotos secuestren la sesión de la cesta de un cliente mediante Cross-Site Request Forgery (CSRF) si se cumplen los siguientes requisitos: (1) el atacante conoce qué tienda está siendo empleada actualmente por el cliente; (2) el atacante sabe en qué momento exacto añadirá el cliente productos en la cesta; (3) el atacante sabe qué productos están ya en la cesta (debe conocer los ID de los artículos) y (4) el atacante podría engañar a un usuario para que haga clic en un botón (formulario de envío) de un email o sitio remoto en el período entre que se visita la tienda y se realiza un pedido."
    }
  ],
  "lastModified": "2026-06-17T01:03:15.777",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oxid-esales:eshop:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FEEDC08-0C1C-4116-8AE5-49CD7D425EC1",
              "versionEndExcluding": "4.9.10",
              "versionStartIncluding": "4.9.0"
            },
            {
              "criteria": "cpe:2.3:a:oxid-esales:eshop:*:*:*:*:professional:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33F13A43-3670-4D55-BD70-5E26ACA45CCC",
              "versionEndExcluding": "4.9.10",
              "versionStartIncluding": "4.9.0"
            },
            {
              "criteria": "cpe:2.3:a:oxid-esales:eshop:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AF4EC8F-7117-4DD0-BD1E-2B044D642FC0",
              "versionEndExcluding": "4.10.5",
              "versionStartIncluding": "4.10.0"
            },
            {
              "criteria": "cpe:2.3:a:oxid-esales:eshop:*:*:*:*:professional:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A69D17A-994A-48EC-9B4F-01257A68BF53",
              "versionEndExcluding": "4.10.5",
              "versionStartIncluding": "4.10.0"
            },
            {
              "criteria": "cpe:2.3:a:oxid-esales:eshop:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5CE46B4B-7F2A-4629-BDBC-FD2FCB969E75",
              "versionEndExcluding": "5.2.10",
              "versionStartIncluding": "5.2.0"
            },
            {
              "criteria": "cpe:2.3:a:oxid-esales:eshop:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F650109B-FF62-4837-B0EC-1A9B0ECA05A5",
              "versionEndExcluding": "5.3.5",
              "versionStartIncluding": "5.3.0"
            },
            {
              "criteria": "cpe:2.3:a:oxid-esales:eshop:6.0.0:rc1:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B70B24C9-3B67-4577-B91E-DEA55FDBA401"
            },
            {
              "criteria": "cpe:2.3:a:oxid-esales:eshop:6.0.0:rc1:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A019B397-0B3D-4BC2-BD89-D704718D9ED0"
            },
            {
              "criteria": "cpe:2.3:a:oxid-esales:eshop:6.0.0:rc1:*:*:professional:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "913BA158-23AE-4129-9533-0091496460B9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}