Description
An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress File Upload Arbitrary File Upload (3.8.5)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5293)
phpMyFAQ Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-0788)
Magento Improper Authorization Vulnerability (CVE-2021-21026)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2026-58026)