GHSA-qqcr-9jfc-35c4HighCVSS 7.5
OXID eShop May Display User Information
🔗 CVE IDs covered (1)
📋 Description
An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a Smarty syntax error.
🎯 Affected products3
- composer/oxid-esales/oxideshop-ce:>= 6.0.0, < 6.14.4
- composer/oxid-esales/oxideshop-metapackage-ce:>= 6.0.0, < 6.5.5
- composer/oxid-esales/smarty-component:< 1.0.1