A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email address.
References
Link | Resource |
---|---|
https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-11-05 15:15
Updated : 2019-11-06 09:31
NVD link : CVE-2019-8120
Mitre link : CVE-2019-8120
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
magento
- magento