← Back

CVE-2019-7874

nvd nist
Published: Aug 2, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of user roles.

Affected (3)

Products: Magento: Magento
1 product
Magento
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Magento
From 2.1.0 to 2.1.18
From 2.2.0 to 2.2.9
From 2.3.0 to 2.3.2

Timeline

No history available yet.