#VU30897 Improper Authorization in Magento Open Source - CVE-2019-7872


| Updated: 2020-07-17

Vulnerability identifier: #VU30897

Vulnerability risk: Medium

CVSSv4.0: 6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2019-7872

CWE-ID: CWE-285

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Magento Open Source
Web applications / E-Commerce systems

Vendor: Adobe

Description

The vulnerability allows a remote privileged user to read and manipulate data.

An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to insufficient authorizations checks. This can be abused by a user with admin privileges to add users to company accounts or modify existing user details.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Magento Open Source: 2.3.0 - 2.3.1


External links
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability