The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.
References
Configurations
History
No history.
Information
Published : 2020-04-30 14:15
Updated : 2024-11-21 04:59
NVD link : CVE-2020-12101
Mitre link : CVE-2020-12101
CVE.ORG link : CVE-2020-12101
JSON object : View
Products Affected
xt-commerce
- xt-commerce
CWE
CWE-276
Incorrect Default Permissions