We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without requiring password re-authentication. An attacker with temporary access to an authenticated session (e.g., on a shared/public machine) could permanently delete the user’s account without knowledge of the password. This bypass of re-authentication puts users at risk of account loss and data disruption. Version 1.1.0.3 contains a patch for the issue.
Reserved 2025-05-05 | Published 2025-06-02 | Updated 2025-06-02 | Assigner GitHub_MCWE-306: Missing Authentication for Critical Function
github.com/...ixCart/security/advisories/GHSA-62qj-pvwm-h8cv
github.com/...ommit/e87162b15d31c4126acfc1aad6108e5b9955bb76
Support options