First published: Tue Jun 25 2019(Updated: )
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/product-community-edition | >=2.1<2.1.18>=2.2<2.2.9>=2.3<2.3.2 | |
composer/magento/community-edition | >=2.3<2.3.2 | 2.3.2 |
composer/magento/community-edition | >=2.2<2.2.9 | 2.2.9 |
composer/magento/community-edition | >=2.1<2.1.18 | 2.1.18 |
Magento | >=2.1.0<2.1.18 | |
Magento | >=2.2.0<2.2.9 | |
Magento | >=2.3.0<2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7881 is a moderate severity vulnerability affecting Magento that allows authenticated users to exploit cross-site scripting and escalate privileges.
To fix CVE-2019-7881, upgrade Magento to version 2.1.18, 2.2.9, or 2.3.2 or later.
CVE-2019-7881 affects Magento versions prior to 2.1.18, 2.2.9, and 2.3.2.
CVE-2019-7881 cannot be exploited remotely; it requires an authenticated user.
CVE-2019-7881 is associated with cross-site scripting (XSS) attacks.