Remote Code Execution Vulnerability in Magento by eBay Inc.
CVE-2019-8150
8.8HIGH
What is CVE-2019-8150?
A remote code execution vulnerability allows authenticated users with permissions to alter layouts and images in Magento versions prior to 2.2.10 and 2.3.3 to inject malicious payloads into the page layout. This could potentially lead to unauthorized actions being performed on the system. To mitigate this risk, users should update their Magento installations to the latest versions to ensure that security patches are applied effectively.
Affected Version(s)
Magento 2 Magento 2.2 prior to 2.2.10
Magento 2 Magento 2.3 prior to 2.3.3 or 2.3.2-p1