{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-19T18:38:38.342","vulnerabilities":[{"cve":{"id":"CVE-2025-47272","sourceIdentifier":"security-advisories@github.com","published":"2025-06-02T11:15:22.557","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without requiring password re-authentication. An attacker with temporary access to an authenticated session (e.g., on a shared/public machine) could permanently delete the user’s account without knowledge of the password. This bypass of re-authentication puts users at risk of account loss and data disruption. Version 1.1.0.3 contains a patch for the issue."},{"lang":"es","value":"La plataforma CE Phoenix eCommerce, a partir de la versión 1.0.9.7 y anteriores a la 1.1.0.3, permitía a los usuarios conectados eliminar sus cuentas sin necesidad de volver a autenticar la contraseña. Un atacante con acceso temporal a una sesión autenticada (por ejemplo, en una máquina compartida o pública) podría eliminar permanentemente la cuenta del usuario sin conocer la contraseña. Esta omisión de la reautenticación pone a los usuarios en riesgo de pérdida de cuenta e interrupción de datos. La versión 1.1.0.3 incluye un parche para este problema."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/CE-PhoenixCart/PhoenixCart/commit/e87162b15d31c4126acfc1aad6108e5b9955bb76","source":"security-advisories@github.com"},{"url":"https://github.com/CE-PhoenixCart/PhoenixCart/security/advisories/GHSA-62qj-pvwm-h8cv","source":"security-advisories@github.com"}]}}]}