CVE-2019-8152
- EPSS 0.18%
- Veröffentlicht 06.11.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:49:22
A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse the blockDi...
CVE-2019-8153
- EPSS 0.06%
- Veröffentlicht 06.11.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:49:23
A mitigation bypass to prevent cross-site scripting (XSS) exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Successful exploitation of this vulnerability would result in an attacker being able to bypass the `escapeURL()` ...
CVE-2019-8154
- EPSS 1.13%
- Veröffentlicht 06.11.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:49:23
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to modify product catalogs can trigger PHP file inclusion through a crafted XML file that speci...
CVE-2019-8155
- EPSS 0.07%
- Veröffentlicht 06.11.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:49:23
Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.
- EPSS 1.63%
- Veröffentlicht 06.11.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:49:23
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges can execute aribitrary code through arbitrary file deletion and OS com...
CVE-2019-8227
- EPSS 2.14%
- Veröffentlicht 06.11.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:49:31
In Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code via import / export functionality when creating profile action XML.
CVE-2019-8228
- EPSS 2.14%
- Veröffentlicht 06.11.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:49:31
in Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code into transactional email page when creating a new email template or editing existing email te...
CVE-2019-8136
- EPSS 0.18%
- Veröffentlicht 06.11.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:49:21
An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.
CVE-2019-8137
- EPSS 0.54%
- Veröffentlicht 06.11.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:49:21
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate CMS section of the website can trigger remote code execution via custom layout up...
CVE-2019-8138
- EPSS 0.18%
- Veröffentlicht 06.11.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:49:21
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked...