Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f98m-7gfc-g33x

Опубликовано: 04 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium-severity issue allows the mass creation of accounts. This could affect database storage; also, non-requested storefront accounts can be created on behalf of visitors.

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium-severity issue allows the mass creation of accounts. This could affect database storage; also, non-requested storefront accounts can be created on behalf of visitors.

EPSS

Процентиль: 36%
0.00155
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.9
nvd
около 1 года назад

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium-severity issue allows the mass creation of accounts. This could affect database storage; also, non-requested storefront accounts can be created on behalf of visitors.

EPSS

Процентиль: 36%
0.00155
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-862