View Issue Details

IDProjectCategoryView StatusLast Update
0007997OXID eShop (all versions)4.04. Securitypublic2026-08-20 07:41
Reportersuabo Assigned To 
PrioritynormalSeverityminorReproducibilityalways
Status newResolutionopen 
Product Version6.5.4 
Summary0007997: Password Reset Token Exposure Via Web Cache Poisoning Leads To Account Takeover
DescriptionWe have found that we are able to steal password reset token/link and takeover the account completely due to web cache poisoning vulnerability exploit.
Steps To Reproduce1) Open Any Password Reset link
2) Navigate to some links
3) Click Back Button
4) The Page will show the password reset token/link
5) Enter Password.
6) Click Save.
7) Password Successfully Changed.
8) Complete Account Takeover
Additional InformationImpact:
Attackers will be able to take over any user account due to this vulnerability exploit (Web cache poisoning)
- Information Exposure
- Account Takeover

Attack Scenario:
If a user of your application is using a shared PC or using internet cafe, The intruder can come and easily take over the account of any user due to this vulnerability exploit.

Mitigation:
Properly validate web cache on password reset token/links. Once the new links are navigated the old web cache should automatically expire for the prevention of password reset tokens stealing due to web cache vulnerability exploit.
TagsNo tags attached.
ThemeNot defined
BrowserNot defined
PHP VersionNot defined
Database VersionNot defined

Activities

There are no notes attached to this issue.