Vulnerabilities > XT Commerce
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-04-30 | CVE-2020-12101 | Incorrect Default Permissions vulnerability in Xt-Commerce The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address. | 4.3 |