CVE-2019-8231

In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.
References
Link Resource
https://magento.com/security/patches/supee-11219 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*

History

No history.

Information

Published : 2019-11-06 00:15

Updated : 2024-02-28 17:28


NVD link : CVE-2019-8231

Mitre link : CVE-2019-8231

CVE.ORG link : CVE-2019-8231


JSON object : View

Products Affected

magento

  • magento