First published: Tue Nov 05 2019(Updated: )
In Magento Open Source prior to 1.9.4.3, and Magento Commerce prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/core | <1.9.4.3 | 1.9.4.3 |
CentOS Libgcc | >=1.5.0.0<1.9.4.3 | |
CentOS Libgcc | >=1.9.0.0<1.14.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8231 is classified as a critical vulnerability due to the potential for arbitrary code execution by an authenticated user with administrative privileges.
To resolve CVE-2019-8231, upgrade Magento Open Source to version 1.9.4.3 or later, and Magento Commerce to version 1.14.4.3 or later.
CVE-2019-8231 affects all users of Magento Open Source versions prior to 1.9.4.3 and Magento Commerce versions prior to 1.14.4.3.
CVE-2019-8231 can allow an authenticated user to execute arbitrary code, potentially leading to full system compromise.
Yes, exploitation of CVE-2019-8231 requires the attacker to have administrative privileges within the Magento platform.