Code Execution Vulnerability in Magento by Adobe
CVE-2019-8229
7.2HIGH
What is CVE-2019-8229?
An arbitrary code execution vulnerability exists in Magento versions before 1.9.4.3 and 1.14.4.3. An authenticated administrator, when editing product attributes, can exploit crafted layout updates to execute arbitrary code. This potentially allows attackers to gain unauthorized control over system components and data, posing significant security risks.
Affected Version(s)
Magento 1 Magento Open Source prior to 1.9.4.3
Magento 1 and Magento Commerce prior to 1.14.4.3