Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-01-08T22:00:00Z

Updated: 2024-09-17T02:47:31.707Z

Reserved: 2018-01-08T00:00:00Z

Link: CVE-2018-5301

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-01-08T22:29:00.213

Modified: 2018-02-02T18:11:31.667

Link: CVE-2018-5301

cve-icon Redhat

No data.