A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
References
Link | Resource |
---|---|
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-08-02 22:15
Updated : 2024-02-28 17:08
NVD link : CVE-2019-7947
Mitre link : CVE-2019-7947
CVE.ORG link : CVE-2019-7947
JSON object : View
Products Affected
magento
- magento
CWE
CWE-352
Cross-Site Request Forgery (CSRF)