Improper access control in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - #VU8486

 

Improper access control in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - #VU8486

Published: September 15, 2017


Vulnerability identifier: #VU8486
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to modify order fields.

The vulnerability exists due to improper access controls. A remote attacker can can modify order fields that they do not have permission to view.


Affected software

Magento Open Source
Adobe Commerce (formerly Magento Commerce)

Remediation

The vulnerability is addressed in the following versions:
Magento Open Source 1.9.3.6, Magento Commerce 1.14.3.6, Magento 2.0.16 and 2.1.9.


External References

Related Security Bulletins