Information disclosure in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - #VU8459
Published: September 15, 2017
Vulnerability identifier: #VU8459
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The disclosed vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can craft a URL request on a Magento site during checkout and retrieve information about past orders.
Affected software
Magento Open Source
Adobe Commerce (formerly Magento Commerce)
Adobe Commerce (formerly Magento Commerce)
Remediation
The vulnerability is addressed in the following versions:
Magento Open Source 1.9.3.6, Magento Commerce 1.14.3.6, Magento 2.0.16 and 2.1.9.
Magento Open Source 1.9.3.6, Magento Commerce 1.14.3.6, Magento 2.0.16 and 2.1.9.