Vulnerabilities > CVE-2020-16194 - Authorization Bypass Through User-Controlled Key vulnerability in Store-Opart Quote

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
store-opart
CWE-639

Summary

An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.

Vulnerable Configurations

Part Description Count
Application
Store-Opart
1