X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove request.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| X-cart | Qualiteam | * | 5.1.10 (including) |
References