Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Layno

#48020of 53,612
5.3Total CVSS
Vulnerabilities · 1
PT-2021-9868
5.3
2021-02-04
Unknown · Prestashop Opart Devis · CVE-2020-16194
**Name of the Vulnerable Software and Affected Versions** Prestashop Opart devis versions prior to 4.0.2 **Description** An Insecure Direct Object Reference (IDOR) issue allows unauthenticated attackers to access any user's invoice and delivery address by exploiting the `delivery address` and `invoice address` fields. **Recommendations** For Prestashop Opart devis versions prior to 4.0.2, update to version 4.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the `delivery address` and `invoice address` fields until a patch is applied.