View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0007997 | OXID eShop (all versions) | 4.04. Security | public | 2026-08-20 07:41 | 2026-08-20 07:41 |
| Reporter | suabo | Assigned To | |||
| Priority | normal | Severity | minor | Reproducibility | always |
| Status | new | Resolution | open | ||
| Product Version | 6.5.4 | ||||
| Summary | 0007997: Password Reset Token Exposure Via Web Cache Poisoning Leads To Account Takeover | ||||
| Description | We have found that we are able to steal password reset token/link and takeover the account completely due to web cache poisoning vulnerability exploit. | ||||
| Steps To Reproduce | 1) Open Any Password Reset link 2) Navigate to some links 3) Click Back Button 4) The Page will show the password reset token/link 5) Enter Password. 6) Click Save. 7) Password Successfully Changed. 8) Complete Account Takeover | ||||
| Additional Information | Impact: Attackers will be able to take over any user account due to this vulnerability exploit (Web cache poisoning) - Information Exposure - Account Takeover Attack Scenario: If a user of your application is using a shared PC or using internet cafe, The intruder can come and easily take over the account of any user due to this vulnerability exploit. Mitigation: Properly validate web cache on password reset token/links. Once the new links are navigated the old web cache should automatically expire for the prevention of password reset tokens stealing due to web cache vulnerability exploit. | ||||
| Tags | No tags attached. | ||||
| Theme | Not defined | ||||
| Browser | Not defined | ||||
| PHP Version | Not defined | ||||
| Database Version | Not defined | ||||