An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x. By using a specially crafted URL, users with administrative rights could unintentionally grant unauthorized users access to the admin panel via session fixation.
| Software | From | Fixed in |
|---|---|---|
| oxid-esales / eshop | 4.9.0 | 4.10.0.x |
| oxid-esales / eshop | 5.2.0 | 5.3.0.x |
| oxid-esales / eshop | 6.1.0 | 6.1.5 |
| oxid-esales / eshop | 6.0.0 | 6.0.6 |