Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-5301.json"