Junglewise Threat Intelligence

CVE-2024-56526: OXID eShop information disclosure via Smarty syntax errors

CVE-2024-56526 · Severity: high · CVSS 7.5 · Published 2025-05-13

Vendors: Packagist.

Executive brief

OXID eShop, a popular e-commerce platform, contains a vulnerability that could lead to the accidental disclosure of sensitive user information. When a Content Management System (CMS) page contains a specific template error, the system may inadvertently display private user data to unauthorized visitors. This could result in a breach of customer privacy and potential regulatory compliance issues.

Technical details

An information disclosure vulnerability (CWE-200) exists in OXID eShop versions prior to 7.0. The issue occurs when CMS pages are used in conjunction with the Smarty templating engine. If a CMS page contains a Smarty syntax error, the resulting error handling or rendering process may leak sensitive user information to the response. The vulnerability is reachable over the network without authentication or user interaction. Patches have been released in versions 6.14.4 (CE), 6.5.5 (Metapackage), and 1.0.1 (Smarty component).

Affected products

  • OXID eSales OXID eShop CE >= 6.0.0, < 6.14.4
  • OXID eSales OXID eShop Metapackage CE >= 6.0.0, < 6.5.5
  • OXID eSales Smarty Component < 1.0.1

Timeline

  • 2025-05-13: disclosed
  • 2025-05-13: advisory
  • 2025-05-14: patched

References

Related threats