VULNERABILITY INTELLIGENCE
CVE-2014-2017
CVSS score6.1 MEDIUM
EPSS probability2.40%
CISA KEVNot currently listed
Published2018-01-18
Last modified2026-06-17
Description
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response... .