CVE-2020-12101

The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:xt-commerce:xt\:commerce:*:*:*:*:*:*:*:*

Information

Published : 2020-04-30 07:15

Updated : 2020-05-06 11:32


NVD link : CVE-2020-12101

Mitre link : CVE-2020-12101


JSON object : View

CWE
CWE-276

Incorrect Default Permissions

Advertisement

dedicated server usa

Products Affected

xt-commerce

  • xt\