First published: Tue Jun 25 2019(Updated: )
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to customer configurations to inject malicious javascript.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/magento1ee | >=1<1.14.4.2 | |
composer/magento/product-community-edition | >=2.1<2.1.18>=2.2<2.2.9>=2.3<2.3.2 | |
composer/magento/magento1ce | >=1<1.9.4.2 | |
composer/magento/community-edition | >=2.3.0<2.3.2 | 2.3.2 |
composer/magento/community-edition | >=2.2.0<2.2.9 | 2.2.9 |
composer/magento/community-edition | >=2.1.0<2.1.18 | 2.1.18 |
Magento | <1.9.4.2 | |
Magento | <1.14.4.2 | |
Magento | >=2.1.0<2.1.18 | |
Magento | >=2.2.0<2.2.9 | |
Magento | >=2.3.0<2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7897 is classified as a stored cross-site scripting vulnerability with a high severity rating.
To remediate CVE-2019-7897, update to Magento Open Source version 1.9.4.2 or later, Magento Commerce version 1.14.4.2 or later, or the appropriate Magento 2 versions: 2.1.18, 2.2.9, and 2.3.2.
CVE-2019-7897 affects authenticated users with privileges on affected versions of Magento Open Source and Commerce.
Affected versions include Magento Open Source prior to 1.9.4.2 and Magento 2.0 before 2.3.2, along with various versions in between.
Yes, CVE-2019-7897 can be exploited by authenticated users to inject malicious scripts into the admin panel.