CVE-2026-21359: Magento customer address handling did not verify address ownership before use. getAddressById() (Address/Book.php) and validateDefaultAddress() (CustomerRepository.php) now confirm the address belongs to the current customer, preventing an authenticated user from reading or assigning another customer's address (IDOR / CWE-863, CVSS... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
Customer Address IDOR / Authorization Bypass in Magento
Reagiere als Erste:r — dein Feedback zählt!
SOCIAL SHARE CARD GENERATOR