CVE-2019-7947: CSRF
A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
Other sources
PRODSECBUG-2387: Cross site request forgery attacks are possible via the gift card removal feature
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7947?
CVE-2019-7947 is classified as a medium severity cross-site request forgery vulnerability.
How do I fix CVE-2019-7947?
To fix CVE-2019-7947, update to Magento Open Source version 2.1.18, 2.2.9, 2.3.2, or corresponding Magento Commerce versions.
Which versions are affected by CVE-2019-7947?
CVE-2019-7947 affects Magento Open Source versions prior to 2.1.18, 2.2.9, 2.3.2, and Magento Commerce versions before 1.14.4.2 and 1.9.4.2.
What type of vulnerability is CVE-2019-7947?
CVE-2019-7947 is a cross-site request forgery (CSRF) vulnerability.
Is CVE-2019-7947 specific to certain Magento products?
Yes, CVE-2019-7947 specifically affects Magento Open Source and Magento Commerce products.