Improper access control in Magento Open Source - #VU18719
Published: June 10, 2019
Magento Open Source
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions of the Insecure direct object reference in the application. A remote authenticated attacker can enumerate and access unauthorized wishlist via insecure direct object reference in the application.