CVE-2019-8147: XSS
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via customer attribute label.
Other sources
PRODSECBUG-2398: Cross-Site Scripting via Customer Attribute Labels
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8147?
CVE-2019-8147 is classified as a stored cross-site scripting (XSS) vulnerability in Magento.
How do I fix CVE-2019-8147?
To fix CVE-2019-8147, upgrade Magento to version 2.2.10 or 2.3.3, or apply the appropriate patches if available.
Which versions of Magento are affected by CVE-2019-8147?
CVE-2019-8147 affects Magento versions 2.2 prior to 2.2.10 and 2.3 prior to 2.3.3 or 2.3.2-p1.
What type of vulnerability is CVE-2019-8147?
CVE-2019-8147 is a stored cross-site scripting (XSS) vulnerability that allows an authenticated user to inject JavaScript.
What impact does CVE-2019-8147 have on Magento users?
CVE-2019-8147 can lead to unauthorized JavaScript execution, which may compromise user data and site integrity.