CVE-2019-7880
- EPSS 0.11%
- Veröffentlicht 02.08.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:48:54
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to marketing email template...
CVE-2019-7881
- EPSS 0.1%
- Veröffentlicht 02.08.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:48:54
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).
CVE-2019-7882
- EPSS 0.1%
- Veröffentlicht 02.08.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:48:54
A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenti...
CVE-2019-7885
- EPSS 0.63%
- Veröffentlicht 02.08.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:48:54
Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This vulnerability could be abused by an auth...
CVE-2019-7886
- EPSS 0.1%
- Veröffentlicht 02.08.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:48:55
A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is used to generate the intialization vector in multiple security relevant contexts.
CVE-2019-7887
- EPSS 0.1%
- Veröffentlicht 02.08.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:48:55
A reflected cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 when the fea...
CVE-2019-7888
- EPSS 0.11%
- Veröffentlicht 02.08.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:48:55
An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates could leak sensitive data via a malicious email tem...
CVE-2019-7889
- EPSS 0.1%
- Veröffentlicht 02.08.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:48:55
An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with marketing manipulation ...
CVE-2019-7890
- EPSS 0.09%
- Veröffentlicht 02.08.2019 22:15:16
- Zuletzt bearbeitet 21.11.2024 04:48:55
An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.
CVE-2019-7857
- EPSS 0.03%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:52
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can cause unwanted items to be added to a shopper's cart due to an insufficiently robust anti-CSRF token implementation.