Stored Cross-Site Scripting Vulnerability in Magento Products from Adobe
CVE-2019-8152
5.4MEDIUM
Summary
A stored cross-site scripting (XSS) vulnerability exists in Magento versions prior to 1.9.4.3 and 1.14.4.3, as well as Magento 2.2 versions prior to 2.2.10 and 2.3 versions prior to 2.3.3 or 2.3.2-p1. This vulnerability allows an authenticated user with access to the WYSIWYG editor to exploit the blockDirective() function, enabling the injection of malicious JavaScript. This code can be executed upon loading the admin dashboard, potentially compromising sensitive data and the integrity of the application.
Affected Version(s)
Magento 1 & 2 Magento Open Source prior to 1.9.4.3
Magento 1 & 2 and Magento Commerce prior to 1.14.4.3
Magento 1 & 2 Magento 2.2 prior to 2.2.10
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved