First published: Tue Jun 25 2019(Updated: )
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to newsletter templates.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/magento1ce | >=1<1.9.4.2 | |
composer/magento/product-community-edition | >=2.1<2.1.18>=2.2<2.2.9>=2.3<2.3.2 | |
composer/magento/magento1ee | >=1<1.14.4.2 | |
composer/magento/community-edition | >=2.3.0<2.3.2 | 2.3.2 |
composer/magento/community-edition | >=2.2.0<2.2.9 | 2.2.9 |
composer/magento/community-edition | >=2.1.0<2.1.18 | 2.1.18 |
Magento | <1.9.4.2 | |
Magento | <1.14.4.2 | |
Magento | >=2.1.0<2.1.18 | |
Magento | >=2.2.0<2.2.9 | |
Magento | >=2.3.0<2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7875 is considered a high severity stored cross-site scripting vulnerability.
To fix CVE-2019-7875, you need to upgrade to Magento Open Source version 1.9.4.2 or later, Magento Commerce version 1.14.4.2 or later, and the respective patches for Magento 2.1, 2.2, and 2.3.
CVE-2019-7875 affects authenticated users with privileges in Magento Open Source and Magento Commerce versions prior to the specified updates.
CVE-2019-7875 can be exploited to execute stored cross-site scripting attacks, potentially compromising user sessions.
CVE-2019-7875 was publicly disclosed as a vulnerability affecting various Magento versions.