Show filters
360 Total Results
Displaying 311-320 of 360
Sort by:
Attacker Value
Unknown

CVE-2019-7855

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used in gift card generation.
0
Attacker Value
Unknown

CVE-2019-7854

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details.
0
Attacker Value
Unknown

CVE-2019-7897

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to customer configurations to inject malicious javascript.
0
Attacker Value
Unknown

CVE-2019-7911

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to the admin panel to manipulate system configuration and execute arbitrary code.
0
Attacker Value
Unknown

CVE-2019-7852

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file path could result in a redirect to the URL of the Magento admin panel, disclosing its location to potentially unauthorized parties.
0
Attacker Value
Unknown

CVE-2019-7950

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API calls to assign themselves to an arbitrary company, thereby gaining read access to potentially confidental information.
0
Attacker Value
Unknown

CVE-2019-7853

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the tax notifications configuration in the Magento admin panel.
0
Attacker Value
Unknown

CVE-2019-7857

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can cause unwanted items to be added to a shopper's cart due to an insufficiently robust anti-CSRF token implementation.
0
Attacker Value
Unknown

CVE-2019-7939

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by sending a victim a crafted URL that results in malicious javascript execution in the victim's browser.
0
Attacker Value
Unknown

CVE-2019-7947

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
0