Remote Code Execution Vulnerability in Magento by eBay Inc.
CVE-2019-8150
8.8HIGH
Summary
A remote code execution vulnerability allows authenticated users with permissions to alter layouts and images in Magento versions prior to 2.2.10 and 2.3.3 to inject malicious payloads into the page layout. This could potentially lead to unauthorized actions being performed on the system. To mitigate this risk, users should update their Magento installations to the latest versions to ensure that security patches are applied effectively.
Affected Version(s)
Magento 2 Magento 2.2 prior to 2.2.10
Magento 2 Magento 2.3 prior to 2.3.3 or 2.3.2-p1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved