CVE-2019-7925

All FrameworksMagentoCWE-OtherCVE-2019-7925

CVE-2019-7925

State: PUBLISHED · Published: 2019-08-02 · Updated: 2024-08-04 · Assigner: adobe
Description
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an administrator with limited privileges to delete the downloadable products folder.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2019/7xxx/CVE-2019-7925.json