Viewing Issues 1 - 12 / 12

    PSeverityTarget VersionIDUpdated StatusCategorySummary
  crash00074152024-08-081
resolved
1.05. Users
It's possible to partly hijack an account, in case the user provides an URL containing the parameter force_sid
  minor00066992024-05-162
resolved
2.3. Extensions (modules, themes)
Two issues with the serialized basket
  minor00057442023-12-061
resolved
4.09. SEO, SEO URL
Switching language in category "more" redirects to startpage
  crash00070592022-08-223
resolved
1.05. Users
CreateUser does not check CSRF/session token
  minor00066592017-07-263
resolved
2.3. Extensions (modules, themes)
Deactivating a module which extends basket causes shop maintenance mode
  major00057712016-03-234
resolved
1.03. Basket, checkout process
Previous users cart details are shown to another user
  minor4.8.9 / 5.1.900057752015-07-082
resolved
4.06. Language and translations
DefaultLanguage collabs language selection in frontend
  major4.7.14 / 5.0.1400058092014-07-251
resolved
4.04. Security
Session ID Disclosure
  major4.7.8 / 5.0.800053462013-10-07 
resolved
2. ----- eShop backend (admin) -----
When there are a sid set in cookies and admin page has wysiwyg editor, user gets logged out
  major4.8.0_5.1.0_beta100042622013-05-293
resolved
4.07. Source code, Test
Change in oxSession::getBasket leads to sideeffect in oxutilsobject::_makeSafeModuleClassParents
  minor4.7.6 / 5.0.600051062013-05-061
resolved
1.05. Users
error messages do not disappear
  minor00014292012-12-101
resolved
4.07. Source code, Test
"remoteaccess" parameter does not disable cookie check