Improper access control in Magento Open Source - #VU18719

 

Improper access control in Magento Open Source - #VU18719

Published: June 10, 2019


Vulnerability identifier: #VU18719
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.

The vulnerability exists due to improper access restrictions of the Insecure direct object reference in the application. A remote authenticated attacker can enumerate and access unauthorized wishlist via insecure direct object reference in the application.


Affected software

Magento Open Source

Remediation

Install updates from vendor's website.

Magento Open Source - addressed in versions 2.1.17, 2.2.8, 2.3.1

External References

Related Security Bulletins