CVE-2019-7923: SSRF
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by authenticated user with admin privileges to manipulate shipment settings to execute arbitrary code.
Other sources
PRODSECBUG-2339: Arbitrary code execution due to unsafe handling of a carrier gateway
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7923?
CVE-2019-7923 is considered a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2019-7923?
To fix CVE-2019-7923, upgrade Magento to version 2.1.18, 2.2.9, or 2.3.2.
Who can exploit CVE-2019-7923?
CVE-2019-7923 can be exploited by authenticated users with admin privileges.
What types of attacks can CVE-2019-7923 facilitate?
CVE-2019-7923 allows attackers to manipulate shipment settings and execute arbitrary code.
Which versions of Magento are affected by CVE-2019-7923?
CVE-2019-7923 affects Magento versions 2.1 prior to 2.1.18, 2.2 prior to 2.2.9, and 2.3 prior to 2.3.2.