Stored Cross-Site Scripting Vulnerability in Magento Products from Adobe
CVE-2019-8152

5.4MEDIUM

Key Information:

Vendor
Adobe
Vendor
CVE Published:
6 November 2019

Summary

A stored cross-site scripting (XSS) vulnerability exists in Magento versions prior to 1.9.4.3 and 1.14.4.3, as well as Magento 2.2 versions prior to 2.2.10 and 2.3 versions prior to 2.3.3 or 2.3.2-p1. This vulnerability allows an authenticated user with access to the WYSIWYG editor to exploit the blockDirective() function, enabling the injection of malicious JavaScript. This code can be executed upon loading the admin dashboard, potentially compromising sensitive data and the integrity of the application.

Affected Version(s)

Magento 1 & 2 Magento Open Source prior to 1.9.4.3

Magento 1 & 2 and Magento Commerce prior to 1.14.4.3

Magento 1 & 2 Magento 2.2 prior to 2.2.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.