The admin controllers that start, create and save an order shipment checked the broad 'Magento_Sales::shipment' ACL resource instead of the narrower 'Magento_Sales::ship' one, so an admin user granted only read access to shipments could still create and save them. A low-privileged authenticated admin can therefore bypass the intended permission... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
Improper Authorization in Magento Admin Shipment Controllers
Reagiere als Erste:r — dein Feedback zählt!
SOCIAL SHARE CARD GENERATOR