CVE-2019-8117: XSS
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticates user can inject arbitrary JavaScript code via product view id specification.
Other sources
PRODSECBUG-2455: Stored cross-site scripting (XSS) from URL in to product page
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8117?
CVE-2019-8117 has a medium severity rating due to its potential for enabling stored cross-site scripting (XSS) attacks.
How do I fix CVE-2019-8117?
To fix CVE-2019-8117, upgrade Magento to version 2.2.10 or 2.3.3 and later releases.
Who can exploit CVE-2019-8117?
CVE-2019-8117 can be exploited by authenticated users who can manipulate product view ID specifications.
Which versions of Magento are affected by CVE-2019-8117?
CVE-2019-8117 affects Magento versions 2.2 prior to 2.2.10 and 2.3 prior to 2.3.3 or 2.3.2-p1.
What kind of attack is possible with CVE-2019-8117?
CVE-2019-8117 allows for a stored cross-site scripting (XSS) attack, enabling attackers to inject arbitrary JavaScript code.