CVE-2019-7872

MEDIUM

Magento <2.1.18-2.3.2 - SSRF

Title source: llm
STIX 2.1

Description

An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to insufficient authorizations checks. This can be abused by a user with admin privileges to add users to company accounts or modify existing user details.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0009
EPSS Percentile 25.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-639
Status published
Products (2)
magento/community-edition 2.1 - 2.1.18Packagist
magento/magento 2.1.0 - 2.1.18
Published Aug 02, 2019
Tracked Since Feb 18, 2026