CVE-2025-52920
Last modified
CVE-2025-52920 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers and the deletion of their reviews of products on the website. To be specific, an attacker could view the order details of any order by browsing to /en/account/orders/_ORDER_ID_ or use the address and billing information of other customers by manipulating the shipping_address_id and billing_address_id parameters when making an order (this information is then reflected in the receipt). Additionally, an attacker could delete the reviews of other users by sending a DELETE request to /en/account/reviews/_REVIEW_ID.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-52920?
How severe is CVE-2025-52920?
How do I fix CVE-2025-52920?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-52915K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware…7.2
- CVE-2025-52916Yealink RPS before 2025-06-04 lacks SN verification attempt …2.2
- CVE-2025-52917The Yealink RPS API before 2025-05-26 lacks rate limiting, p…4.3
- CVE-2025-52918Yealink RPS before 2025-05-26 does not prevent OpenAPI acces…5
- CVE-2025-52919In Yealink RPS before 2025-05-26, the certificate upload fun…4.3
- CVE-2025-5292The Element Pack Addons for Elementor – Best Elementor addon…6.4
- CVE-2025-52921In Innoshop through 0.4.1, an authenticated attacker could e…9.9
- CVE-2025-52922Innoshop through 0.4.1 allows directory traversal via FileMa…7.4
- CVE-2025-52923Sangfor aTrust through 2.4.10 allows users to modify the Exe…4.3
- CVE-2025-52924In One Identity OneLogin before 2025.2.0, the SQL connection…4
- CVE-2025-52925In One Identity OneLogin Active Directory Connector before 6…5
- CVE-2025-52926In scan.rs in spytrap-adb before 0.3.5, matches for known st…2.7
Are you affected by CVE-2025-52920?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
