CVE-2019-8235
Estado: ModificadaMedia (6.5)—
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. An authenticated user may be able to view personally identifiable shipping details of another user due to insufficient validation of user controlled input.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.88%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-639
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-8235",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "Adobe",
"product": "Magento",
"versions": [
{
"status": "affected",
"version": "2.3 prior to 2.3.1"
},
{
"status": "affected",
"version": "2.2 prior to 2.2.8"
},
{
"status": "affected",
"version": "2.1 prior to 2.1.17"
}
]
}
]
}
],
"published": "2019-10-30T00:15:12.740",
"references": [
{
"url": "https://magento.com/security/patches/magento-2.3.1-2.2.8-and-2.1.17-security-update",
"tags": [
"Vendor Advisory"
],
"source": "psirt@adobe.com"
},
{
"url": "https://magento.com/security/patches/magento-2.3.1-2.2.8-and-2.1.17-security-update",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-639"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. An authenticated user may be able to view personally identifiable shipping details of another user due to insufficient validation of user controlled input."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de referencia directa a objeto (IDOR) no segura en Magento versiones 2.3 anteriores a 2.3.1, versiones 2.2 anteriores a 2.2.8 y versiones 2.1 anteriores a 2.1.17. Un usuario autenticado puede visualizar los detalles de envío identificables personalmente de otro usuario debido a una comprobación insuficiente de una entrada controlada por el usuario."
}
],
"lastModified": "2026-06-17T02:41:43.223",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCA87878-4437-418E-8D19-D40674FBEE1D",
"versionEndExcluding": "2.1.17",
"versionStartIncluding": "2.1.0"
},
{
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B7B6D6D-3481-4E8D-B5FC-D06AC7B727F1",
"versionEndExcluding": "2.1.17",
"versionStartIncluding": "2.1.0"
},
{
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5AF193BC-1111-4879-BEC2-5423F3EA3D85",
"versionEndExcluding": "2.2.8",
"versionStartIncluding": "2.2.0"
},
{
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7B7D3EB-54DB-4B69-A4EE-61F44328C371",
"versionEndExcluding": "2.2.8",
"versionStartIncluding": "2.2.0"
},
{
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F1D18BC-47FA-4BAD-8BDD-0DF4779531CE",
"versionEndExcluding": "2.3.1",
"versionStartIncluding": "2.3.0"
},
{
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "050A96AF-2F85-476F-A704-6540C8895362",
"versionEndExcluding": "2.3.1",
"versionStartIncluding": "2.3.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@adobe.com"
}