4
CVSSv2

CVE-2020-12101

Published: 30/04/2020 Updated: 29/04/2024
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xt-commerce xt-commerce

Exploits

xt:Commerce version 541, 621, and 622 suffer from an improper access control vulnerability A logged-in customer can create and alter addresses These addresses are referenced by incrementing IDs On saving an address, an attacker could change the ID of the address to write the data to If the ID belongs to an address which does not belong to ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [SYSS-2020-012] Improper Access Control (CWE-284) in xt:Commerce (CVE-2020-12101) <!--X-Subject-Header-End--> <!--X-He ...