Lucene search

K
cveMitreCVE-2014-9025
HistoryNov 20, 2014 - 5:50 p.m.

CVE-2014-9025

2014-11-2017:50:14
CWE-200
mitre
web.nvd.nist.gov
22
cve-2014-9025
drupal commerce
commerce_order module
information security
remote attackers

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

69.6%

The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email address as the username for new accounts created at checkout, which allows remote attackers to obtain sensitive information via unspecified vectors.

Affected configurations

Nvd
Node
commerceguyscommerceMatch7.x-1.0drupal
OR
commerceguyscommerceMatch7.x-1.0alpha1drupal
OR
commerceguyscommerceMatch7.x-1.0alpha2drupal
OR
commerceguyscommerceMatch7.x-1.0alpha3drupal
OR
commerceguyscommerceMatch7.x-1.0alpha4drupal
OR
commerceguyscommerceMatch7.x-1.0alpha5drupal
OR
commerceguyscommerceMatch7.x-1.0beta1drupal
OR
commerceguyscommerceMatch7.x-1.0beta2drupal
OR
commerceguyscommerceMatch7.x-1.0beta3drupal
OR
commerceguyscommerceMatch7.x-1.0beta4drupal
OR
commerceguyscommerceMatch7.x-1.0rc1drupal
OR
commerceguyscommerceMatch7.x-1.0rc2drupal
OR
commerceguyscommerceMatch7.x-1.0rc3drupal
OR
commerceguyscommerceMatch7.x-1.1drupal
VendorProductVersionCPE
commerceguyscommerce7.x-1.0cpe:2.3:a:commerceguys:commerce:7.x-1.0:*:*:*:*:drupal:*:*
commerceguyscommerce7.x-1.0cpe:2.3:a:commerceguys:commerce:7.x-1.0:alpha1:*:*:*:drupal:*:*
commerceguyscommerce7.x-1.0cpe:2.3:a:commerceguys:commerce:7.x-1.0:alpha2:*:*:*:drupal:*:*
commerceguyscommerce7.x-1.0cpe:2.3:a:commerceguys:commerce:7.x-1.0:alpha3:*:*:*:drupal:*:*
commerceguyscommerce7.x-1.0cpe:2.3:a:commerceguys:commerce:7.x-1.0:alpha4:*:*:*:drupal:*:*
commerceguyscommerce7.x-1.0cpe:2.3:a:commerceguys:commerce:7.x-1.0:alpha5:*:*:*:drupal:*:*
commerceguyscommerce7.x-1.0cpe:2.3:a:commerceguys:commerce:7.x-1.0:beta1:*:*:*:drupal:*:*
commerceguyscommerce7.x-1.0cpe:2.3:a:commerceguys:commerce:7.x-1.0:beta2:*:*:*:drupal:*:*
commerceguyscommerce7.x-1.0cpe:2.3:a:commerceguys:commerce:7.x-1.0:beta3:*:*:*:drupal:*:*
commerceguyscommerce7.x-1.0cpe:2.3:a:commerceguys:commerce:7.x-1.0:beta4:*:*:*:drupal:*:*
Rows per page:
1-10 of 141

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

69.6%

Related for CVE-2014-9025