Show filters
49 Total Results
Displaying 31-40 of 49
Sort by:
Attacker Value
Unknown
CVE-2019-8152
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse the blockDirective() function and inject malicious javascript in the cache of the admin dashboard.
0
Attacker Value
Unknown
CVE-2019-8135
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remote code execution.
0
Attacker Value
Unknown
CVE-2019-8149
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.
0
Attacker Value
Unknown
CVE-2019-8109
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution.
0
Attacker Value
Unknown
CVE-2019-8113
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1 uses cryptographically weak random number generator to brute-force the confirmation code for customer registration.
0
Attacker Value
Unknown
CVE-2019-8116
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a successful login to gain access to customer account index page.
0
Attacker Value
Unknown
CVE-2019-8124
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An insufficient logging and monitoring vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Failure to track admin actions related to design configuration could lead to repudiation attacks.
0
Attacker Value
Unknown
CVE-2019-8093
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage file upload controller for downloadable products to read/delete an arbitary files.
0
Attacker Value
Unknown
CVE-2019-8127
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to an account with Newsletter Template editing permission could exfiltrate the Admin login data, and reset their password, effectively performing a privilege escalation.
0
Attacker Value
Unknown
CVE-2019-8126
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document type definition and XML layout allow processing of external entities which can lead to information disclosure.
0