CVE-2019-7858
- EPSS 0.05%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:52
A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive information with an algorithm that is insufficiently resistant to brute force attacks.
CVE-2019-7859
- EPSS 0.14%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:52
A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could result in unauthorized access to uploaded images due to insufficient access control.
CVE-2019-7860
- EPSS 0.1%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:52
A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
CVE-2019-7861
- EPSS 0.06%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:52
Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
CVE-2019-7862
- EPSS 0.1%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:52
A reflected cross-site scripting vulnerability exists in the Product widget chooser functionality in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
CVE-2019-7863
- EPSS 0.11%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:52
A stored cross-site scripting vulnerability exists in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to products and categories.
CVE-2019-7864
- EPSS 0.06%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:53
An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.
CVE-2019-7865
- EPSS 0.06%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:53
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.
CVE-2019-7866
- EPSS 0.11%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:53
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to edit Product information via t...
CVE-2019-7867
- EPSS 0.11%
- Veröffentlicht 02.08.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:48:53
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to manage orders and order status...