CVE-2019-8131: XSS
Published Oct 8, 2019
·Updated
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into code field of an inventory source.
Other sources
PRODSECBUG-2423: Cross-Site Scripting via inventory source
Affected Software
9 affected componentsFixes available
composer/magento/product-community-edition>=2.2, <2.2.10, >=2.3, <2.3.2-p2
composer/magento/community-edition>=2.3.0<2.3.2-p1
2.3.2-p1
composer/magento/community-edition>=2.2.0<2.2.10
2.2.10
Magento Magento>=2.2.0<2.2.10
Magento Magento>=2.2.0<2.2.10
Magento Magento>=2.3.0<2.3.2
Magento Magento>=2.3.0<2.3.2
Magento Magento=2.3.2
Magento Magento=2.3.2
Remediation
Event History
Oct 8, 2019
Advisory Published
12:00 AM
Nov 5, 2019
CVE Published
via MITRE·11:07 PM
Data Sourced
via MITRE·11:07 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-8131?
CVE-2019-8131 has a moderate severity level due to its ability to allow XSS attacks by authenticated users.
2
How do I fix CVE-2019-8131?
To fix CVE-2019-8131, upgrade to Magento version 2.2.10 or 2.3.2-p1 or later.
3
Who is affected by CVE-2019-8131?
CVE-2019-8131 affects Magento versions prior to 2.2.10 and 2.3.2-p1.
4
What type of vulnerability is CVE-2019-8131?
CVE-2019-8131 is a stored cross-site scripting (XSS) vulnerability.
5
How can CVE-2019-8131 be exploited?
CVE-2019-8131 can be exploited by authenticated users injecting malicious JavaScript code into inventory source fields.