CVE-2014-9025: Infoleak
The default checkout completion rule in the commerceorder module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email address as the username for new accounts created at checkout, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9025?
CVE-2014-9025 is classified as a moderate severity vulnerability that allows remote attackers to access sensitive information.
How do I fix CVE-2014-9025?
To fix CVE-2014-9025, upgrade the Drupal Commerce module to version 7.x-1.10 or later.
What systems are affected by CVE-2014-9025?
CVE-2014-9025 affects Drupal Commerce module versions 7.x-1.0 to 7.x-1.9.
What type of vulnerability is CVE-2014-9025?
CVE-2014-9025 is a security vulnerability stemming from improper handling of email addresses as usernames during checkout.
Can CVE-2014-9025 lead to account compromise?
Yes, CVE-2014-9025 can potentially lead to account compromise by exposing sensitive information to attackers.