CVE-2023-26260: Oxidforge Oxid Eshop
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.
Affected products
- Oxidforge Oxid Eshop: from 6.2.0, before 6.5.2 (fixed in 6.5.2)
Published 2023-04-11. Last modified 2026-06-17.