CVE-2019-7854
—CVSS 3.0
7.5 high
EPSS
1%p65
Published
()
Modified
Description
An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details.
- Vendors
- magento
- Products
- magento
- Ecosystems
- E-commerce
- Weakness
- CWE-639
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.