CVE-2017-3211

Yopify, an e-commerce notification plugin, up to April 06, 2017, leaks the first name, last initial, city, and recent purchase data of customers, all without user authorization.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yopify:yopify:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:25

Type Values Removed Values Added
References () https://blog.rapid7.com/2017/05/31/r7-2017-05-centire-yopify-information-disclosure-cve-2017-3211/ - Exploit, Third Party Advisory () https://blog.rapid7.com/2017/05/31/r7-2017-05-centire-yopify-information-disclosure-cve-2017-3211/ - Exploit, Third Party Advisory

Information

Published : 2020-01-15 17:15

Updated : 2024-11-21 03:25


NVD link : CVE-2017-3211

Mitre link : CVE-2017-3211

CVE.ORG link : CVE-2017-3211


JSON object : View

Products Affected

yopify

  • yopify
CWE
CWE-213

Exposure of Sensitive Information Due to Incompatible Policies

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor