Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-41879


Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.


Published

2023-09-11T22:15:08.267

Last Modified

2024-11-21T08:21:50.350

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-330

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openmage magento < 19.5.1 Yes
Application openmage magento < 20.1.1 Yes

References