Show filters
360 Total Results
Displaying 261-270 of 360
Sort by:
Attacker Value
Unknown
CVE-2019-8107
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An arbitrary file deletion vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with export data transfer privileges can craft a request to perform arbitrary file deletion.
0
Attacker Value
Unknown
CVE-2019-8120
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email address.
0
Attacker Value
Unknown
CVE-2019-8112
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can bypass the email confirmation mechanism via GET request that captures relevant account data obtained from the POST response related to new user creation.
0
Attacker Value
Unknown
CVE-2019-8121
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.
0
Attacker Value
Unknown
CVE-2019-8110
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage email templates hierarchy to manipulate the interceptor class in a way that allows an attacker to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-8115
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when adding an image for during simple product creation.
0
Attacker Value
Unknown
CVE-2019-8118
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 uses weak cryptographic function to store the failed login attempts for customer accounts.
0
Attacker Value
Unknown
CVE-2019-8114
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to import features can execute arbitrary code via crafted configuration archive file upload.
0
Attacker Value
Unknown
CVE-2019-8123
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An insufficient logging and monitoring vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. The logging feature required for effective monitoring did not contain sufficent data to effectively track configuration changes.
0
Attacker Value
Unknown
CVE-2019-8091
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3. An authenticated admin user with privileges to access product attributes can leverage layout updates to trigger remote code execution.
0