GHSA-3pgc-7jf3-5x5g
GitHub Security Advisory
Magento 2 Community Edition IDOR Vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.
Affected Packages
Packagist
magento/community-edition
Affected versions:
2.1
(fixed in 2.1.18)
Packagist
magento/community-edition
Affected versions:
2.2
(fixed in 2.2.9)
Packagist
magento/community-edition
Affected versions:
2.3
(fixed in 2.3.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 31, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.