CVE Database
/

CVE-2019-8152

Back to search

CVE-2019-8152

Published: Nov 5, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse the blockDirective() function and inject malicious javascript in the cache of the admin dashboard.

VendorProductVersions

Adobe Systems Incorporated

Magento 1 & 2

affected
Magento Open Source prior to 1.9.4.3
affected
and Magento Commerce prior to 1.14.4.3
affected
Magento 2.2 prior to 2.2.10
affected
Magento 2.3 prior to 2.3.3 or 2.3.2-p1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now