CVE-2019-8145: XSS
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into the attribute set name when listing the products.
Other sources
PRODSECBUG-2402: Cross-Site Scripting via Attribute Set Name
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8145?
The severity of CVE-2019-8145 is considered medium due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2019-8145?
To fix CVE-2019-8145, upgrade to Magento versions 2.2.10 or 2.3.3 and later.
Who is affected by CVE-2019-8145?
CVE-2019-8145 affects Magento versions 2.2 prior to 2.2.10 and 2.3 prior to 2.3.3 or 2.3.2-p1.
What type of vulnerability is CVE-2019-8145?
CVE-2019-8145 is a stored cross-site scripting (XSS) vulnerability.
What can an attacker do with CVE-2019-8145?
An attacker can inject arbitrary JavaScript code into the attribute set name when listing products due to CVE-2019-8145.