CVE-2019-7864Authorization Bypass Through User-Controlled Key in Magento

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 81.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDmagento/magento2.1.02.1.18+2
Packagistmagento/community-edition2.1.02.1.18+2
CVEListV5adobe_systems_incorporated/magento_2Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2

🔴Vulnerability Details

3
OSV
Magento 2 Community Edition IDOR Vulnerability2022-05-24
GHSA
Magento 2 Community Edition IDOR Vulnerability2022-05-24
CVEList
CVE-2019-7864: An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 22019-08-02

💥Exploits & PoCs

1
Exploit-DB
Centreon 19.04 - Authenticated Remote Code Execution (Metasploit)2020-01-20
CVE-2019-7864 — Magento vulnerability | cvebase