CVE-2019-7863

A stored cross-site scripting vulnerability exists in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to products and categories.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*

History

No history.

Information

Published : 2019-08-02 22:15

Updated : 2024-02-28 17:08


NVD link : CVE-2019-7863

Mitre link : CVE-2019-7863

CVE.ORG link : CVE-2019-7863


JSON object : View

Products Affected

magento

  • magento
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')