{"api_version":"1","generated_at":"2026-07-23T12:31:52+00:00","cve":"CVE-2019-7854","urls":{"html":"https://cve.report/CVE-2019-7854","api":"https://cve.report/api/cve/CVE-2019-7854.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-7854","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-7854"},"summary":{"title":"CVE-2019-7854","description":"An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details.","state":"PUBLIC","assigner":"psirt@adobe.com","published_at":"2019-08-02 22:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-639"],"metrics":[],"references":[{"url":"https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23","name":"https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Magento 2.3.2, 2.2.9 and 2.1.18 Security Update 2/3 | Magento","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-7854","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-7854","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"7854","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"magento","cpe5":"magento","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"open_source","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"7854","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"magento","cpe5":"magento","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"open_source","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-7854","ASSIGNER":"psirt@adobe.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Magento 2","version":{"version_data":[{"version_value":"Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Insecure Direct Object Reference"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23","url":"https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23"}]},"description":{"description_data":[{"lang":"eng","value":"An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details."}]}},"nvd":{"publishedDate":"2019-08-02 22:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-639"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*","versionStartIncluding":"2.1.0","versionEndExcluding":"2.1.18","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*","versionStartIncluding":"2.2.0","versionEndExcluding":"2.2.9","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*","versionStartIncluding":"2.3.0","versionEndExcluding":"2.3.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"7854","Ordinal":"145687","Title":"CVE-2019-7854","CVE":"CVE-2019-7854","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"7854","Ordinal":"1","NoteData":"An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"7854","Ordinal":"2","NoteData":"2019-08-02","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"7854","Ordinal":"3","NoteData":"2019-08-02","Type":"Other","Title":"Modified"}]}}}