Medium severity4.3NVD Advisory· Published Apr 30, 2020· Updated Jun 17, 2026
CVE-2020-12101
CVE-2020-12101
Description
The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:xt-commerce:xt-commerce:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:xt-commerce:xt-commerce:*:*:*:*:*:*:*:*range: >=5.1.0,<=6.2.2
- (no CPE)range: 5.1 to 6.2.2
- xt:Commerce/xt:Commercedescription
Patches
Vulnerability mechanics
References
4- helpdesk.xt-commerce.com/index.phpnvdPatchVendor Advisory
- packetstormsecurity.com/files/157534/xt-Commerce-5.4.1-6.2.1-6.2.2-Improper-Access-Control.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2020/May/0nvdExploitMailing ListPatchThird Party Advisory
- www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-012.txtnvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.