First published: Tue Jun 25 2019(Updated: )
A reflected cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 when the feature that adds a secret key to the Admin URL is disabled.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/product-community-edition | >=2.1<2.1.18>=2.2<2.2.9>=2.3<2.3.2 | |
composer/magento/magento1ce | >=1<1.9.4.2 | |
composer/magento/magento1ee | >=1<1.14.4.2 | |
composer/magento/community-edition | >=2.3.0<2.3.2 | 2.3.2 |
composer/magento/community-edition | >=2.2.0<2.2.9 | 2.2.9 |
composer/magento/community-edition | >=2.1.0<2.1.18 | 2.1.18 |
Magento | <1.9.4.2 | |
Magento | <1.14.4.2 | |
Magento | >=2.1.0<2.1.18 | |
Magento | >=2.2.0<2.2.9 | |
Magento | >=2.3.0<2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7887 is classified as a reflected cross-site scripting vulnerability.
To fix CVE-2019-7887, upgrade to Magento Open Source version 1.9.4.2 or later, Magento Commerce version 1.14.4.2 or later, Magento 2.1 version 2.1.18 or later, Magento 2.2 version 2.2.9 or later, or Magento 2.3 version 2.3.2 or later.
CVE-2019-7887 affects Magento Open Source versions prior to 1.9.4.2, and Magento Commerce versions prior to 1.14.4.2, as well as specific versions of Magento 2.1, 2.2, and 2.3.
Yes, CVE-2019-7887 is exploitable remotely through the Magento admin panel.
If CVE-2019-7887 is exploited, it can allow attackers to execute arbitrary JavaScript in the context of the victim's browser.