Vulnerabilities > XT Commerce

DATE CVE VULNERABILITY TITLE RISK
2020-04-30 CVE-2020-12101 Incorrect Default Permissions vulnerability in Xt-Commerce
The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.
network
low complexity
xt-commerce CWE-276
4.3