CVE-2019-7864

MEDIUM

Magento <2.1.18-2.3.2 - SSRF

Title source: llm
STIX 2.1

Description

An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0006
EPSS Percentile 18.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-639
Status published
Products (2)
magento/community-edition 2.1.0 - 2.1.18Packagist
magento/magento 2.1.0 - 2.1.18
Published Aug 02, 2019
Tracked Since Feb 18, 2026