CVE detail
CVE-2023-41879 — CVE-2023-41879
Published 2023-09-11 · Modified 2026-06-17 · Vendor openmage · Product magento · Source nvd
HIGH
severity
CVSS-derived band
0.0082
EPSS probability
exploitation probability, 30d
54.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References