CVE-2019-8120: XSS
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email address.
Other sources
PRODSECBUG-2448: Cross side scripting via admin panel dashboard
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8120?
CVE-2019-8120 is rated as a moderate severity vulnerability due to the potential for authenticated users to execute arbitrary JavaScript on affected Magento versions.
How do I fix CVE-2019-8120?
To fix CVE-2019-8120, upgrade your Magento installation to version 2.1.19, 2.2.10, or 2.3.3 or later.
What versions are affected by CVE-2019-8120?
CVE-2019-8120 affects Magento versions 2.1 before 2.1.19, 2.2 before 2.2.10, and 2.3 before 2.3.3.
Can CVE-2019-8120 be exploited remotely?
CVE-2019-8120 cannot be exploited remotely as it requires an authenticated user to perform actions that trigger the vulnerability.
What type of vulnerability is CVE-2019-8120?
CVE-2019-8120 is classified as a stored cross-site scripting (XSS) vulnerability.