CVE-2019-8227: XSS
Published Nov 6, 2019
·Updated
In Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code via import / export functionality when creating profile action XML.
Affected Software
3 affected componentsFixes available
composer/magento/core<1.9.4.3
1.9.4.3
Magento Magento>=1.5.0.0<1.9.4.3
Magento Magento>=1.9.0.0<1.14.4.3
Event History
Nov 6, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
May 24, 2022
Advisory Published
via GitHub·05:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-8227?
CVE-2019-8227 has a medium severity rating due to the potential for injection of arbitrary JavaScript code.
2
How do I fix CVE-2019-8227?
To mitigate CVE-2019-8227, upgrade Magento to the latest versions 1.9.4.3 or 1.14.4.3 or later.
3
Who is affected by CVE-2019-8227?
CVE-2019-8227 affects Magento users operating versions prior to 1.9.4.3 for open source and 1.14.4.3 for commerce.
4
What types of users can exploit CVE-2019-8227?
An authenticated user with limited administrative privileges can exploit CVE-2019-8227.
5
What does CVE-2019-8227 allow an attacker to do?
CVE-2019-8227 allows an attacker to inject arbitrary JavaScript code through the import/export functionality in Magento.