An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.
References
| Link | Resource |
|---|---|
| https://github.com/login-securite/CVE/blob/main/CVE-2020-16194.md | Exploit Third Party Advisory |
| https://github.com/login-securite/CVE/blob/main/CVE-2020-16194.md | Exploit Third Party Advisory |
Configurations
History
27 Jan 2026, 21:02
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Store-opart op\'art Devis
|
|
| CPE | cpe:2.3:a:store-opart:op\'art_devis:*:*:*:*:*:prestashop:*:* |
21 Nov 2024, 05:06
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/login-securite/CVE/blob/main/CVE-2020-16194.md - Exploit, Third Party Advisory |
Information
Published : 2021-02-04 15:15
Updated : 2026-01-27 21:02
NVD link : CVE-2020-16194
Mitre link : CVE-2020-16194
CVE.ORG link : CVE-2020-16194
JSON object : View
Products Affected
store-opart
- op\'art_devis
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
