CVE-2020-16194: Store-Opart Op'art Devis

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.

Affected products

  • Store-Opart Op'art Devis: before 4.0.2 (fixed in 4.0.2)

Published 2021-02-04. Last modified 2026-06-17.