Show filters
360 Total Results
Displaying 281-290 of 360
Sort by:
Attacker Value
Unknown
CVE-2019-7926
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify node attributes to inject malicious javascript.
0
Attacker Value
Unknown
CVE-2019-7928
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A denial-of-service (DoS) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. By abusing insufficient brute-forcing defenses in the token exchange protocol, an unauthenticated attacker could disrupt transactions between the Magento merchant and PayPal.
0
Attacker Value
Unknown
CVE-2019-7923
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by authenticated user with admin privileges to manipulate shipment settings to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-7898
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to inadequate validation of user input.
0
Attacker Value
Unknown
CVE-2019-7935
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify content page titles to inject malicious javascript.
0
Attacker Value
Unknown
CVE-2019-7881
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).
0
Attacker Value
Unknown
CVE-2019-7934
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to edit newsletter templates to inject malicious javascript.
0
Attacker Value
Unknown
CVE-2019-7865
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.
0
Attacker Value
Unknown
CVE-2019-7851
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from customer pages.
0
Attacker Value
Unknown
CVE-2019-7849
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2, Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2.
0