An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium-severity issue allows the mass creation of accounts. This could affect database storage; also, non-requested storefront accounts can be created on behalf of visitors.
History

Mon, 06 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 04 Jan 2025 02:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium-severity issue allows the mass creation of accounts. This could affect database storage; also, non-requested storefront accounts can be created on behalf of visitors.
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-04T00:00:00

Updated: 2025-01-06T15:13:34.352Z

Reserved: 2025-01-04T00:00:00

Link: CVE-2025-22385

cve-icon Vulnrichment

Updated: 2025-01-06T15:13:19.736Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-04T02:15:07.080

Modified: 2025-01-06T16:15:32.017

Link: CVE-2025-22385

cve-icon Redhat

No data.