An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates could leak sensitive data via a malicious email template.
References
Link | Resource |
---|---|
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-08-02 15:15
Updated : 2021-07-21 04:39
NVD link : CVE-2019-7888
Mitre link : CVE-2019-7888
JSON object : View
CWE
Products Affected
magento
- magento