Vulnerabilities
Vulnerable Software
Magento:  >> Magento  >> 2.1.12  Security Vulnerabilities
An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details.
CVSS Score
7.5
EPSS Score
0.001
Published
2019-08-02
A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used in gift card generation.
CVSS Score
5.3
EPSS Score
0.002
Published
2019-08-02
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
CVSS Score
9.8
EPSS Score
0.413
Published
2019-04-10


Contact Us

Shodan ® - All rights reserved