CVE-2019-8142: XSS
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via title of an order when configuring sales payment methods for a store.
Other sources
PRODSECBUG-2406: Cross-Site Scripting via Payment Method Title
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8142?
CVE-2019-8142 is considered a high-severity stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2019-8142?
To fix CVE-2019-8142, upgrade Magento to version 2.2.10, 2.3.3, or 2.3.2-p1 or later.
What versions of Magento are affected by CVE-2019-8142?
CVE-2019-8142 affects Magento 2.2 versions prior to 2.2.10 and 2.3 versions prior to 2.3.3 or 2.3.2-p1.
Can an attacker exploit CVE-2019-8142 without authentication?
No, exploitation of CVE-2019-8142 requires an authenticated user to inject the arbitrary JavaScript code.
What are the potential impacts of CVE-2019-8142 on a Magento store?
Exploitation of CVE-2019-8142 could lead to unauthorized actions on behalf of users, including data theft or account compromise.