Stored Cross-Site Scripting Vulnerability in Magento by Adobe
CVE-2019-8142
5.4MEDIUM
Summary
A stored cross-site scripting vulnerability in Adobe's Magento allows authenticated users to inject arbitrary JavaScript code into the title field of an order during the configuration of sales payment methods. This flaw affects multiple versions prior to Magento 2.2.10 and 2.3.3, posing a security risk that could lead to exploitation if not addressed. Users are encouraged to apply relevant security updates to safeguard their systems.
Affected Version(s)
Magento 2 Magento 2.2 prior to 2.2.10
Magento 2 Magento 2.3 prior to 2.3.3 or 2.3.2-p1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved