CVE-2018-5763: Oxid-Esales Eshop
Medium severity, CVSS 5.9. EPSS: 1.1% chance of exploitation in the next 30 days.
An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used.
Affected products
- Oxid-Esales Eshop: before 5.3.7 (fixed in 5.3.7); version 6.0.0 only
Published 2018-02-19. Last modified 2026-06-17.