← Back

CVE-2019-8152

nvd nist
Published: Nov 6, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse the blockDirective() function and inject malicious javascript in the cache of the admin dashboard.

Affected (8)

Products: Magento: Magento
1 product
Magento
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Magento
From 1.9.0.0 to 1.14.4.3
From 2.2.0 to 2.2.10
From 2.3.0 to 2.3.2
From 1.5.0.0 to 1.9.4.3
From 2.2.0 to 2.2.10
From 2.3.0 to 2.3.2
Version 2.3.2
Version 2.3.2

References (2)

Source: psirt@adobe.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.