CVE-2019-8143: SQL Injection
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.
Other sources
PRODSECBUG-2405: Injection vulnerability via email templates
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8143?
CVE-2019-8143 is categorized as a high severity SQL injection vulnerability.
How do I fix CVE-2019-8143?
To fix CVE-2019-8143, upgrade your Magento installation to version 2.2.10 or 2.3.3 and above.
Who is affected by CVE-2019-8143?
CVE-2019-8143 affects authenticated users of Magento 2.2 versions prior to 2.2.10 and Magento 2.3 versions prior to 2.3.3.
What type of vulnerability is CVE-2019-8143?
CVE-2019-8143 is a SQL injection vulnerability that allows attackers to access sensitive database information.
Can exploiting CVE-2019-8143 lead to data breaches?
Yes, exploiting CVE-2019-8143 can result in unauthorized access to sensitive data stored in the database.