Description
An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-8160 | An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields. |
References
History
Tue, 27 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Store-opart op\'art Devis
|
|
| CPEs | cpe:2.3:a:store-opart:op\'art_devis:*:*:*:*:*:prestashop:*:* | |
| Vendors & Products |
Store-opart quote
|
Store-opart op\'art Devis
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T13:37:54.093Z
Reserved: 2020-07-31T00:00:00.000Z
Link: CVE-2020-16194
No data.
Status : Modified
Published: 2021-02-04T15:15:12.967
Modified: 2026-01-27T21:02:44.810
Link: CVE-2020-16194
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD