CVE-2015-0951: Qualiteam X-Cart

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove request.

Affected products

Published 2015-04-05. Last modified 2026-06-17.