CVE-2019-7881

A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*

History

No history.

Information

Published : 2019-08-02 22:15

Updated : 2024-02-28 17:08


NVD link : CVE-2019-7881

Mitre link : CVE-2019-7881

CVE.ORG link : CVE-2019-7881


JSON object : View

Products Affected

magento

  • magento
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')