CVE-2019-8132: XSS
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Name field for Email template in the "Design Configuration" dashboard.
Other sources
PRODSECBUG-2422: Cross-Site Scripting via Email Template Name
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8132?
CVE-2019-8132 has a medium severity rating, allowing authenticated users to execute stored cross-site scripting (XSS) attacks.
How do I fix CVE-2019-8132?
To fix CVE-2019-8132, upgrade Magento to version 2.2.10 or 2.3.3 or later.
Who is affected by CVE-2019-8132?
CVE-2019-8132 affects Magento versions 2.2 prior to 2.2.10 and 2.3 prior to 2.3.3.
What type of vulnerability is CVE-2019-8132?
CVE-2019-8132 is classified as a stored cross-site scripting (XSS) vulnerability.
Can CVE-2019-8132 be exploited remotely?
CVE-2019-8132 requires authentication, meaning it can be exploited by logged-in users against the application.