CVE-2019-8146: XSS
Published Oct 8, 2019
·Updated
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code when adding a new customer attribute for stores.
Other sources
PRODSECBUG-2401: Cross-Site Scripting via Customer Attribute Option Value
Affected Software
9 affected componentsFixes available
composer/magento/product-community-edition>=2.2, <2.2.10, >=2.3, <2.3.2-p2
composer/magento/community-edition>=2.3.0<2.3.2-p2
2.3.2-p2
composer/magento/community-edition>=2.2.0<2.2.10
2.2.10
Magento Magento>=2.2.0<2.2.10
Magento Magento>=2.2.0<2.2.10
Magento Magento>=2.3.0<2.3.2
Magento Magento>=2.3.0<2.3.2
Magento Magento=2.3.2
Magento Magento=2.3.2
Remediation
Event History
Oct 8, 2019
Advisory Published
12:00 AM
Nov 5, 2019
CVE Published
via MITRE·11:31 PM
Data Sourced
via MITRE·11:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-8146?
CVE-2019-8146 has been categorized as a medium severity vulnerability due to the possibility of stored cross-site scripting attacks.
2
How do I fix CVE-2019-8146?
To fix CVE-2019-8146, upgrade Magento to version 2.2.10 or 2.3.3 and later.
3
Who is affected by CVE-2019-8146?
CVE-2019-8146 affects Magento versions 2.2 prior to 2.2.10 and 2.3 prior to 2.3.3.
4
What type of vulnerability is CVE-2019-8146?
CVE-2019-8146 is a stored cross-site scripting (XSS) vulnerability.
5
Can an attacker exploit CVE-2019-8146 without authentication?
No, an attacker must be an authenticated user to exploit CVE-2019-8146.