Improper access control in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - #VU8486
Published: September 15, 2017
Vulnerability identifier: #VU8486
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The disclosed vulnerability allows a remote attacker to modify order fields.
The vulnerability exists due to improper access controls. A remote attacker can can modify order fields that they do not have permission to view.
Affected software
Magento Open Source
Adobe Commerce (formerly Magento Commerce)
Adobe Commerce (formerly Magento Commerce)
Remediation
The vulnerability is addressed in the following versions:
Magento Open Source 1.9.3.6, Magento Commerce 1.14.3.6, Magento 2.0.16 and 2.1.9.
Magento Open Source 1.9.3.6, Magento Commerce 1.14.3.6, Magento 2.0.16 and 2.1.9.