CVE-2019-7927: XSS
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to edit product content pages to inject malicious javascript.
Other sources
PRODSECBUG-2346: Stored cross-site scripting in the admin panel
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7927?
CVE-2019-7927 is classified as a stored cross-site scripting vulnerability with a medium severity that affects Magento versions prior to 2.1.18, 2.2.9, and 2.3.2.
How do I fix CVE-2019-7927?
To fix CVE-2019-7927, you should update your Magento installation to version 2.1.18, 2.2.9, or 2.3.2.
Who is affected by CVE-2019-7927?
CVE-2019-7927 affects authenticated users of Magento versions prior to 2.1.18, 2.2.9, and 2.3.2 with privileges to edit product content pages.
What can an attacker do with CVE-2019-7927?
An attacker exploiting CVE-2019-7927 can inject malicious JavaScript into product content pages through the admin panel.
Is CVE-2019-7927 a critical vulnerability?
CVE-2019-7927 is not classified as critical but poses a significant security risk, especially if exploited in a production environment.