CVE-2020-16194: Store-Opart Op'art Devis
Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.
An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.
Affected products
- Store-Opart Op'art Devis: before 4.0.2 (fixed in 4.0.2)
Published 2021-02-04. Last modified 2026-06-17.