Magento

Magento

222 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Published 06.11.2019 00:15:12
  • Last modified 21.11.2024 04:49:22

A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse the blockDi...

  • EPSS 0.06%
  • Published 06.11.2019 00:15:12
  • Last modified 21.11.2024 04:49:23

A mitigation bypass to prevent cross-site scripting (XSS) exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Successful exploitation of this vulnerability would result in an attacker being able to bypass the `escapeURL()` ...

  • EPSS 1.13%
  • Published 06.11.2019 00:15:12
  • Last modified 21.11.2024 04:49:23

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to modify product catalogs can trigger PHP file inclusion through a crafted XML file that speci...

  • EPSS 0.07%
  • Published 06.11.2019 00:15:12
  • Last modified 21.11.2024 04:49:23

Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.

  • EPSS 1.63%
  • Published 06.11.2019 00:15:12
  • Last modified 21.11.2024 04:49:23

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges can execute aribitrary code through arbitrary file deletion and OS com...

  • EPSS 2.14%
  • Published 06.11.2019 00:15:12
  • Last modified 21.11.2024 04:49:31

In Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code via import / export functionality when creating profile action XML.

  • EPSS 2.14%
  • Published 06.11.2019 00:15:12
  • Last modified 21.11.2024 04:49:31

in Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code into transactional email page when creating a new email template or editing existing email te...

  • EPSS 0.18%
  • Published 06.11.2019 00:15:11
  • Last modified 21.11.2024 04:49:21

An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.

  • EPSS 0.54%
  • Published 06.11.2019 00:15:11
  • Last modified 21.11.2024 04:49:21

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate CMS section of the website can trigger remote code execution via custom layout up...

  • EPSS 0.18%
  • Published 06.11.2019 00:15:11
  • Last modified 21.11.2024 04:49:21

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked...