CVE-2019-8126: XEE
An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document type definition and XML layout allow processing of external entities which can lead to information disclosure.
Other sources
PRODSECBUG-2440: Information disclosure through processing of external XML entities
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8126?
CVE-2019-8126 has been assigned a significant severity level due to its ability to allow XML entity injection by authenticated admin users.
How do I fix CVE-2019-8126?
To fix CVE-2019-8126, update Magento to version 2.2.10 or 2.3.3 or later.
Who is affected by CVE-2019-8126?
CVE-2019-8126 affects Magento versions 2.2 prior to 2.2.10 and 2.3 prior to 2.3.3 or 2.3.2-p1.
What type of vulnerability is CVE-2019-8126?
CVE-2019-8126 is an XML entity injection vulnerability that potentially allows attackers to manipulate the XML layout.
Can I still use Magento versions affected by CVE-2019-8126?
Using affected versions of Magento without applying the security updates leaves your system vulnerable to exploitation.