The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-04-30T13:40:34

Updated: 2024-08-04T11:48:57.835Z

Reserved: 2020-04-23T00:00:00

Link: CVE-2020-12101

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-30T14:15:12.637

Modified: 2024-11-21T04:59:14.773

Link: CVE-2020-12101

cve-icon Redhat

No data.