CVE-2019-8138: XSS
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by sale pickup event.
Other sources
PRODSECBUG-2412: Cross-Site Scripting via Location Name
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8138?
CVE-2019-8138 has been rated as a medium severity vulnerability due to the potential for an authenticated attacker to execute arbitrary JavaScript code.
How do I fix CVE-2019-8138?
To fix CVE-2019-8138, upgrade Magento to version 2.2.10 or 2.3.3 or later.
What versions of Magento are affected by CVE-2019-8138?
CVE-2019-8138 affects Magento versions 2.2.0 to 2.2.9 and 2.3.0 to 2.3.2.
Can CVE-2019-8138 be exploited by unauthenticated users?
No, CVE-2019-8138 can only be exploited by authenticated users with access to the Magento API.
What type of vulnerability is CVE-2019-8138?
CVE-2019-8138 is a stored cross-site scripting (XSS) vulnerability.