Security bulletin: 2009-001

This bulletin has been assigned a CVE identifier of CVE-2009-3112
Released: February 18th, 2009

As part of our regular security audit, the following issue has been identified:


Specially crafted parameter can lead to unauthorized administrative access to shop backend.


Resolved in upcoming OXID eShop release (see below for details). Hotfix for current and older releases is available.


By adding a specially crafted parameter to the URL of the shop backend, unauthorized users may gain administrative privileges. No exploits are known as of today.

Affected products, releases and platforms


  • OXID eShop Professional Edition
  • OXID eShop Enterprise Edition
  • OXID eShop Community Edition




  • Above releases are affected on all platforms.


The issue will be addressed in the following future releases:

  • OXID eShop Professional Edition version 4.1.0
  • OXID eShop Enterprise Edition version 4.1.0
  • OXID eShop Community Edition version 4.1.0

For the currently affected releases, a hotfix is available at All users of OXID eShop should install the hotfix immediately.


There is no workaround. See “Resolution” above.


The security issue has been found during one of our regular security audits.

Stay up-to-date

To receive upcoming OXID Security Bulletins, please subscribe to the mailing lists or the Announcement forum

How to report security issues

Learn how to report security issues in the Security overview page.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *