Lucene search

K
cvelistMitreCVELIST:CVE-2014-9025
HistoryNov 20, 2014 - 5:00 p.m.

CVE-2014-9025

2014-11-2017:00:00
mitre
www.cve.org
1
drupal
commerce
checkout rule
sensitive information

AI Score

6.2

Confidence

Low

EPSS

0.003

Percentile

69.6%

The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email address as the username for new accounts created at checkout, which allows remote attackers to obtain sensitive information via unspecified vectors.

AI Score

6.2

Confidence

Low

EPSS

0.003

Percentile

69.6%

Related for CVELIST:CVE-2014-9025