Issue: The user is unable to open the order PDF.
Steps to regenerate:
- Login at https://demo-trunk.ofbiz.apache.org with a registered user
- Try placing an order with 'Quick Checkout'
- At order confirmation page click on 'PDF'
Reference order: https://demo-trunk.ofbiz.apache.org/ecommerce/control/processorder
Please have a look at the attachment.
- is broken by
OFBIZ-11836 IDOR vulnerability in the order processing feature in ecommerce component (CVE-2020-13923)