First published: Tue Jun 25 2019(Updated: )
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to email templates.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/product-community-edition | >=2.1<2.1.18>=2.2<2.2.9>=2.3<2.3.2 | |
composer/magento/magento1ce | >=1<1.9.4.2 | |
composer/magento/magento1ee | >=1<1.14.4.2 | |
composer/magento/community-edition | >=2.3.0<2.3.2 | 2.3.2 |
composer/magento/community-edition | >=2.2.0<2.2.9 | 2.2.9 |
composer/magento/community-edition | >=2.1.0<2.1.18 | 2.1.18 |
Magento | <1.9.4.2 | |
Magento | <1.14.4.2 | |
Magento | >=2.1.0<2.1.18 | |
Magento | >=2.2.0<2.2.9 | |
Magento | >=2.3.0<2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7909 is classified as a stored cross-site scripting vulnerability, which can allow attackers to execute malicious scripts.
To fix CVE-2019-7909, update Magento to the latest version, specifically 2.3.2 for Magento 2, 2.2.9 for Magento 2.2, and 2.1.18 for Magento 1.
Authenticated users with privileges on affected versions of Magento Open Source and Magento Commerce are at risk from CVE-2019-7909.
CVE-2019-7909 affects Magento Open Source versions prior to 1.9.4.2 and Magento Commerce versions prior to 1.14.4.2, along with several specific versions of Magento 2.
CVE-2019-7909 is a security concern because it allows attackers to inject malicious scripts, potentially compromising the security of the admin panel and the overall system.