CVE-2019-8134: SQL Injection
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with marketing privileges can execute arbitrary SQL queries in the database when accessing email template variables.
Other sources
PRODSECBUG-2418: SQL injection via marketing account with access to email templates variables
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8134?
CVE-2019-8134 has a high severity due to its potential for SQL injection, allowing unauthorized access to the database.
How do I fix CVE-2019-8134?
To fix CVE-2019-8134, upgrade Magento to version 2.2.10 or later for 2.2 series, and to version 2.3.3 or later for the 2.3 series.
What versions of Magento are affected by CVE-2019-8134?
Magento versions 2.2.0 to 2.2.10 and 2.3.0 to 2.3.2-p1 are affected by CVE-2019-8134.
Who can exploit CVE-2019-8134?
CVE-2019-8134 can be exploited by users with marketing privileges within the affected Magento installations.
What type of attack does CVE-2019-8134 enable?
CVE-2019-8134 enables SQL injection attacks that can potentially execute arbitrary SQL queries on the database.