Permissions, Privileges, and Access Controls in Magento Open Source - CVE-2019-7890

 

Permissions, Privileges, and Access Controls in Magento Open Source - CVE-2019-7890

Published: August 3, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30909
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-7890
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Adobe
Affected software:
Magento Open Source

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.


How to mitigate CVE-2019-7890

Install update from vendor's website.

Sources