Show filters
360 Total Results
Displaying 321-330 of 360
Sort by:
Attacker Value
Unknown

CVE-2019-7951

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A SOAP web service endpoint does not properly enforce parameters related to access control. This could be abused to leak customer information via crafted SOAP requests.
0
Attacker Value
Unknown

CVE-2019-7944

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to the Return Product comments field can inject malicious javascript.
0
Attacker Value
Unknown

CVE-2019-7868

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with permissions to manage tax rules.
0
Attacker Value
Unknown

CVE-2019-7909

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to email templates.
0
Attacker Value
Unknown

CVE-2019-7876

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to manipulate layouts can insert a malicious payload into the layout.
0
Attacker Value
Unknown

CVE-2019-7890

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.
0
Attacker Value
Unknown

CVE-2019-7932

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A remote code execution vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with admin privileges to create sitemaps can execute arbitrary PHP code by creating a malicious sitemap file.
0
Attacker Value
Unknown

CVE-2019-7936

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify content block titles to inject malicious javascript.
0
Attacker Value
Unknown

CVE-2019-7927

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to edit product content pages to inject malicious javascript.
0
Attacker Value
Unknown

CVE-2019-7863

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A stored cross-site scripting vulnerability exists in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to products and categories.
0