CVE-2023-41879
11.09.2023, 22:15
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.Enginsight
Vendor | Product | Version |
---|---|---|
openmage | magento | 𝑥 < 19.5.1 |
openmage | magento | 20.0.0 ≤ 𝑥 < 20.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References