VULNERABILITY INTELLIGENCE

CVE-2014-2017

CVSS score6.1 MEDIUM
EPSS probability2.40%
CISA KEVNot currently listed
Published2018-01-18
Last modified2026-06-17

Description

CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response... .