X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove request.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://blog.x-cart.com/5-1-11-released.html | patch vendor advisory |
http://www.kb.cert.org/vuls/id/924124 | third party advisory us government resource |