Show filters
355 Total Results
Displaying 221-230 of 355
Sort by:
Attacker Value
Unknown

CVE-2019-8138

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by sale pickup event.
Attacker Value
Unknown

CVE-2019-8131

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into code field of an inventory source.
Attacker Value
Unknown

CVE-2019-8155

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.
Attacker Value
Unknown

CVE-2019-8148

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when creating a content page via page builder.
Attacker Value
Unknown

CVE-2019-8230

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
In Magentoprior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit configuration settings can execute arbitrary code through a crafted support/output path.
Attacker Value
Unknown

CVE-2019-8159

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges can execute aribitrary code through arbitrary file deletion and OS command injection.
Attacker Value
Unknown

CVE-2019-8128

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting malicious Javascript into the name of main website.
Attacker Value
Unknown

CVE-2019-8130

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with store manipulation privileges can execute arbitrary SQL queries by getting access to the database connection through group instance in email templates.
Attacker Value
Unknown

CVE-2019-8140

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
An unrestricted file upload vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can manipulate the Synchronization feature in the Media File Storage of the database to transform uploaded JPEG file into a PHP file.
Attacker Value
Unknown

CVE-2019-8129

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting an embedded expression into a translation.