Show filters
360 Total Results
Displaying 251-260 of 360
Sort by:
Attacker Value
Unknown

CVE-2019-8116

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a successful login to gain access to customer account index page.
Attacker Value
Unknown

CVE-2019-8124

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An insufficient logging and monitoring vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Failure to track admin actions related to design configuration could lead to repudiation attacks.
Attacker Value
Unknown

CVE-2019-8119

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated admin user with import product privileges can delete files through bulk product import and inject code into XSLT file. The combination of these manipulations can lead to remote code execution.
Attacker Value
Unknown

CVE-2019-8093

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage file upload controller for downloadable products to read/delete an arbitary files.
Attacker Value
Unknown

CVE-2019-8117

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticates user can inject arbitrary JavaScript code via product view id specification.
Attacker Value
Unknown

CVE-2019-8127

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to an account with Newsletter Template editing permission could exfiltrate the Admin login data, and reset their password, effectively performing a privilege escalation.
Attacker Value
Unknown

CVE-2019-8125

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento 1 prior to 1.9.x and 1.14.x. An authenticated admin user can modify configuration parameters via crafted support configuration. The modification can lead to remote code execution.
Attacker Value
Unknown

CVE-2019-8126

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document type definition and XML layout allow processing of external entities which can lead to information disclosure.
Attacker Value
Unknown

CVE-2019-8108

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate session validation setting for a storefront that leads to insecure authentication and session management.
Attacker Value
Unknown

CVE-2019-8092

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via email template preview.