CVE-2019-8139: XSS
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary Javascript code into the dynamic block when invoking page builder on a product.
Other sources
PRODSECBUG-2410: Cross-Site Scripting via Dynamic block in the Page builder
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8139?
CVE-2019-8139 is classified as a stored cross-site scripting (XSS) vulnerability, which can lead to the execution of arbitrary JavaScript code.
How do I fix CVE-2019-8139?
To remediate CVE-2019-8139, upgrade to Magento version 2.3.2-p1 or 2.2.10.
Who is affected by CVE-2019-8139?
CVE-2019-8139 affects users of Magento 2.3 versions prior to 2.3.3 and 2.2 versions prior to 2.2.10.
What can an attacker do with CVE-2019-8139?
An attacker can exploit CVE-2019-8139 to inject and execute arbitrary JavaScript in the context of an authenticated user's session.
Is this vulnerability unique to Magento?
Yes, CVE-2019-8139 specifically affects the Magento platform and its versions mentioned.