CVE-2020-12101

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/04/2020
Last modified:
29/04/2024

Description

The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xt-commerce:xt-commerce:*:*:*:*:*:*:*:* 5.1.0 (including) 6.2.2 (including)