#VU18718 Improper access control in Magento Open Source
Published: June 10, 2019
Magento Open Source
Adobe
Description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to a bypass of authentication controls for a customer using a web API endpoint. A remote authenticated attacker can control other customer's requisition lists by using a web API endpoint to send a request to the server. This overrides the customer_id parameter.