CVE-2019-7911: SSRF
A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to the admin panel to manipulate system configuration and execute arbitrary code.
Other sources
PRODSECBUG-2320: Arbitrary code execution due to unsafe handling of system configuration
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7911?
CVE-2019-7911 has a high severity rating due to its potential for enabling server-side request forgery attacks.
How do I fix CVE-2019-7911?
To mitigate CVE-2019-7911, upgrade to Magento Open Source versions 1.9.4.2 or later, Magento Commerce 1.14.4.2 or later, Magento 2.1.18 or later, 2.2.9 or later, or 2.3.2 or later.
Who is affected by CVE-2019-7911?
Authenticated users with access to the admin panel of affected versions of Magento are vulnerable to CVE-2019-7911.
What types of Magento are impacted by CVE-2019-7911?
CVE-2019-7911 impacts Magento Open Source and Magento Commerce versions prior to the specified patched versions.
Is there a known exploit for CVE-2019-7911?
Yes, CVE-2019-7911 can be exploited through crafted requests by authenticated users with administrative access.