CVE-2022-33077

HIGH

NopCommerce <4.50.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.

Scores

CVSS v3 7.5
EPSS 0.0020
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
nopcommerce/nopcommerce < 4.50.2
Published Oct 19, 2022
Tracked Since Feb 18, 2026