BlackKite: Home
Menu

PUBLISHED DATE: June 2, 2025CVE-2025-47272:
The CE Phoenix eCommerce...

CVSS:
5.5
EPSS:
2.20%
Exploitability:
1.8
In KEV:
No
Description

The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without requiring password re-authentication. An attacker with temporary access to an authenticated session (e.g., on a shared/public machine) could permanently delete the user’s account without knowledge of the password. This bypass of re-authentication puts users at risk of account loss and data disruption. Version 1.1.0.3 contains a patch for the issue.

Questions to Ask Vendors
  1. Can you confirm whether your systems are affected by CVE-2025-47272, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2025-47272 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
References

Ready to get results you can trust?