Back to search
CVE-2020-12101
Published: Apr 30, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20200501 [SYSS-2020-012] Improper Access Control (CWE-284) in xt:Commerce (CVE-2020-12101)
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now