Show filters
49 Total Results
Displaying 11-20 of 49
Sort by:
Attacker Value
Unknown
CVE-2019-8133
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with privileges to generate sitemaps can bypass configuration that restricts directory access. The bypass allows overwrite of a subset of configuration files which can lead to denial of service.
0
Attacker Value
Unknown
CVE-2019-8143
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.
0
Attacker Value
Unknown
CVE-2019-8153
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A mitigation bypass to prevent cross-site scripting (XSS) exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Successful exploitation of this vulnerability would result in an attacker being able to bypass the `escapeURL()` function and execute a malicious XSS payload.
0
Attacker Value
Unknown
CVE-2019-8139
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary Javascript code into the dynamic block when invoking page builder on a product.
0
Attacker Value
Unknown
CVE-2019-8136
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.
0
Attacker Value
Unknown
CVE-2019-8131
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into code field of an inventory source.
0
Attacker Value
Unknown
CVE-2019-8138
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by sale pickup event.
0
Attacker Value
Unknown
CVE-2019-8148
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when creating a content page via page builder.
0
Attacker Value
Unknown
CVE-2019-8159
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges can execute aribitrary code through arbitrary file deletion and OS command injection.
0
Attacker Value
Unknown
CVE-2019-8128
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting malicious Javascript into the name of main website.
0