GHSA-hpxv-vpfv-7jc9
Dashboard / Vulnerabilities / GHSA-hpxv-vpfv-7jc9
Summary: Magento 2 Community Edition IDOR Vulnerability
Details: An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-7854, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-7854.yaml, https://github.com/magento/magento2, https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23, https://web.archive.org/web/20220121051916/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
