CVE-2019-7945: XSS
A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to modify currency symbols can inject malicious javascript.
Other sources
PRODSECBUG-2380: Stored cross-site scripting in the Currency Symbols field
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7945?
CVE-2019-7945 is categorized as a stored cross-site scripting vulnerability.
How do I fix CVE-2019-7945?
To fix CVE-2019-7945, you should upgrade Magento Open Source to version 1.9.4.2 or higher, or Magento Commerce to version 1.14.4.2 or higher.
Which Magento versions are affected by CVE-2019-7945?
CVE-2019-7945 affects Magento Open Source versions prior to 1.9.4.2 and Magento Commerce versions prior to 1.14.4.2.
Who is impacted by CVE-2019-7945?
Authenticated users with privileges to modify currency symbols are impacted by CVE-2019-7945.
Is it safe to continue using software affected by CVE-2019-7945?
No, it is not safe to continue using software affected by CVE-2019-7945 without applying the necessary updates.