CVE-2019-8120
Summary
| CVE | CVE-2019-8120 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-05 23:15:00 UTC |
| Updated | 2019-11-06 17:31:00 UTC |
| Description | A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email address. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Magento | Magento | All | All | All | All |
| Application | Magento | Magento | All | All | All | All |
| Application | Magento | Magento | All | All | All | All |
| Application | Magento | Magento | All | All | All | All |
| Application | Magento | Magento | All | All | All | All |
| Application | Magento | Magento | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Magento 2.3.3 and 2.2.10 Security Update | Magento | MISC | magento.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.