Account Creation Vulnerability in Optimizely Configured Commerce
CVE-2025-22385

Currently unrated

Key Information:

Vendor

Optimizely

Vendor
CVE Published:
4 January 2025

What is CVE-2025-22385?

In Optimizely Configured Commerce prior to version 5.2.2408, a vulnerability has been identified that affects the B2B application regarding user account creation. Newly created accounts are susceptible to mass creation due to the lack of required email confirmation. This oversight poses risks related to database storage management, as it allows the potential for unauthorized storefront accounts to be generated on behalf of unwitting visitors.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.