← Back

CVE-2019-8130

nvd nist
Published: Nov 6, 2019Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with store manipulation privileges can execute arbitrary SQL queries by getting access to the database connection through group instance in email templates.

Affected (6)

Products: Magento: Magento
1 product
Magento
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Magento
From 2.2.0 to 2.2.10
From 2.3.0 to 2.3.2
From 2.2.0 to 2.2.10
From 2.3.0 to 2.3.2
Version 2.3.2
Version 2.3.2

References (2)

Timeline

No history available yet.