CVE-2019-8235

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/10/2019
Last modified:
24/08/2020

Description

An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. An authenticated user may be able to view personally identifiable shipping details of another user due to insufficient validation of user controlled input.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* 2.1.0 (including) 2.1.17 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* 2.1.0 (including) 2.1.17 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* 2.2.0 (including) 2.2.8 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* 2.2.0 (including) 2.2.8 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* 2.3.0 (including) 2.3.1 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* 2.3.0 (including) 2.3.1 (excluding)