PT-2019-18949 · Adobe · Magento
Published
2019-10-29
·
Updated
2020-08-24
·
CVE-2019-8235
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Magento versions 2.1 prior to 2.1.17
Magento versions 2.2 prior to 2.2.8
Magento versions 2.3 prior to 2.3.1
Description
An insecure direct object reference (IDOR) issue exists, allowing an authenticated user to potentially view personally identifiable shipping details of another user due to insufficient validation of user-controlled input.
Recommendations
For Magento version 2.1, update to version 2.1.17 or later.
For Magento version 2.2, update to version 2.2.8 or later.
For Magento version 2.3, update to version 2.3.1 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magento