Executive brief
OXID eShop, a popular e-commerce platform, contains a vulnerability that could lead to the accidental disclosure of sensitive user information. When a Content Management System (CMS) page contains a specific template error, the system may inadvertently display private user data to unauthorized visitors. This could result in a breach of customer privacy and potential regulatory compliance issues.
Technical details
An information disclosure vulnerability (CWE-200) exists in OXID eShop versions prior to 7.0. The issue occurs when CMS pages are used in conjunction with the Smarty templating engine. If a CMS page contains a Smarty syntax error, the resulting error handling or rendering process may leak sensitive user information to the response. The vulnerability is reachable over the network without authentication or user interaction. Patches have been released in versions 6.14.4 (CE), 6.5.5 (Metapackage), and 1.0.1 (Smarty component).
Affected products
- OXID eSales OXID eShop CE >= 6.0.0, < 6.14.4
- OXID eSales OXID eShop Metapackage CE >= 6.0.0, < 6.5.5
- OXID eSales Smarty Component < 1.0.1
Timeline
- 2025-05-13: disclosed
- 2025-05-13: advisory
- 2025-05-14: patched