CVE-2019-7913: SSRF
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to manipulate shipment methods to execute arbitrary code.
Other sources
PRODSECBUG-2322: Arbitrary code execution due to unsafe handling of a shipping gateway
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7913?
CVE-2019-7913 is a critical vulnerability classified as a server-side request forgery (SSRF) that allows an authenticated user with admin privileges to potentially execute arbitrary code.
How do I fix CVE-2019-7913?
To fix CVE-2019-7913, you need to update your Magento installation to version 2.1.18, 2.2.9, or 2.3.2 or later.
Who is affected by CVE-2019-7913?
CVE-2019-7913 affects Magento versions prior to 2.1.18, 2.2.9, and 2.3.2.
What type of vulnerability is CVE-2019-7913?
CVE-2019-7913 is characterized as a server-side request forgery (SSRF) vulnerability.
Can CVE-2019-7913 be exploited remotely?
No, CVE-2019-7913 requires an authenticated user with admin privileges for exploitation.