CVE-2019-8153: XSS
A mitigation bypass to prevent cross-site scripting (XSS) exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Successful exploitation of this vulnerability would result in an attacker being able to bypass the escapeURL() function and execute a malicious XSS payload.
Other sources
PRODSECBUG-2342: Cross-Site Scripting mitigation bypass
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8153?
CVE-2019-8153 has a medium severity level due to its potential to allow cross-site scripting (XSS) attacks.
How do I fix CVE-2019-8153?
To fix CVE-2019-8153, you should upgrade to Magento version 2.2.10 or 2.3.3 and later.
What versions of Magento are affected by CVE-2019-8153?
CVE-2019-8153 affects Magento versions prior to 2.2.10 and 2.3.3 or 2.3.2-p1.
What impact does CVE-2019-8153 have on Magento users?
Exploitation of CVE-2019-8153 could allow attackers to bypass the escapeURL() function, potentially leading to XSS attacks.
Is a patch available for CVE-2019-8153?
Yes, a security update that addresses CVE-2019-8153 is available in the form of Magento versions 2.2.10 and 2.3.3.