An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details.
2019-08-02T22:15:14.910
2024-11-21T04:48:52.000
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | magento | magento | < 2.1.18 | Yes |
Application | magento | magento | < 2.2.9 | Yes |
Application | magento | magento | < 2.3.2 | Yes |