First published: Tue Jun 25 2019(Updated: )
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/product-community-edition | >=2.1<2.1.18>=2.2<2.2.9>=2.3<2.3.2 | |
composer/magento/product-community-edition | >=2.3<2.3.2 | 2.3.2 |
composer/magento/product-community-edition | >=2.2<2.2.9 | 2.2.9 |
composer/magento/product-community-edition | >=2.1<2.1.18 | 2.1.18 |
composer/magento/community-edition | >=2.3.0<2.3.2 | 2.3.2 |
composer/magento/community-edition | >=2.2.0<2.2.9 | 2.2.9 |
composer/magento/community-edition | >=2.1.0<2.1.18 | 2.1.18 |
CentOS Libgcc | >=2.1.0<2.1.18 | |
CentOS Libgcc | >=2.2.0<2.2.9 | |
CentOS Libgcc | >=2.3.0<2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7865 is a critical cross-site request forgery vulnerability affecting specific versions of Magento.
To fix CVE-2019-7865, upgrade your Magento installation to version 2.1.18, 2.2.9, or 2.3.2 or higher.
CVE-2019-7865 impacts Magento versions prior to 2.1.18, 2.2.9, and 2.3.2.
CVE-2019-7865 is classified as a cross-site request forgery (CSRF) vulnerability.
Yes, CVE-2019-7865 can allow unauthorized actions to be performed by exploiting the CSRF vulnerability.