A reflected cross-site scripting vulnerability exists in the Product widget chooser functionality in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
References
Link | Resource |
---|---|
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-08-02 15:15
Updated : 2019-08-06 12:05
NVD link : CVE-2019-7862
Mitre link : CVE-2019-7862
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
magento
- magento