CVE-2019-7925Authorization Bypass Through User-Controlled Key in Magento

Severity
4.9MEDIUMNVD
EPSS
0.0%
top 85.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an administrator with limited privileges to delete the downloadable products folder.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages3 packages

NVDmagento/magento2.1.02.1.18+2
Packagistmagento/community-edition2.12.1.18+2
CVEListV5adobe_systems_incorporated/magento_2Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2

🔴Vulnerability Details

3
OSV
Magento Insecure Direct Object Reference (IDOR) vulnerability2022-05-24
GHSA
Magento Insecure Direct Object Reference (IDOR) vulnerability2022-05-24
CVEList
CVE-2019-7925: An insecure direct object reference (IDOR) vulnerability exists in Magento 22019-08-02
CVE-2019-7925 — Magento vulnerability | cvebase