CVE-2019-7890Authorization Bypass Through User-Controlled Key in Magento

Severity
7.3HIGHNVD
EPSS
0.1%
top 75.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages3 packages

NVDmagento/magento2.1.02.1.18+2
Packagistmagento/community-edition2.12.1.18+2
CVEListV5adobe_systems_incorporated/magento_2Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2

🔴Vulnerability Details

3
OSV
Magento 2 Community Edition IDOR Vulnerability2022-05-24
GHSA
Magento 2 Community Edition IDOR Vulnerability2022-05-24
CVEList
CVE-2019-7890: An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 22019-08-02
CVE-2019-7890 — Magento vulnerability | cvebase