CVE-2019-7850: Command Injection
Published Jun 25, 2019
·Updated
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
Other sources
PRODSECBUG-2116: Stored cross-site scripting in the catalog events feature
Affected Software
4 affected components
composer/magento/product-community-edition>=2.1, <2.1.18, >=2.2, <2.2.9, >=2.3, <2.3.2
Adobe Campaign<=18.10.5.8984
Linux Linux kernel
Microsoft Windows
Event History
Jun 25, 2019
Advisory Published
12:00 AM
Jul 18, 2019
CVE Published
via MITRE·09:43 PM
Data Sourced
via MITRE·09:43 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-7850.
2
What is the title of the vulnerability?
The title of the vulnerability is PRODSECBUG-2116: Stored cross-site scripting in the catalog events feature.
3
What is the affected software?
The affected software is Adobe Campaign Classic version 18.10.5-8984 and earlier versions.
4
What is the severity of CVE-2019-7850?
The severity of CVE-2019-7850 is critical with a severity value of 9.8.
5
How do I fix CVE-2019-7850?
To fix CVE-2019-7850, you should patch your software to the latest version provided by the vendor.