Yopify, an e-commerce notification plugin, up to April 06, 2017, leaks the first name, last initial, city, and recent purchase data of customers, all without user authorization.
References
Link | Resource |
---|---|
https://blog.rapid7.com/2017/05/31/r7-2017-05-centire-yopify-information-disclosure-cve-2017-3211/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-01-15 09:15
Updated : 2020-01-22 08:21
NVD link : CVE-2017-3211
Mitre link : CVE-2017-3211
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
yopify
- yopify