CVE-2019-8231: Code Injection
In Magento Open Source prior to 1.9.4.3, and Magento Commerce prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.
Other sources
In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8231?
CVE-2019-8231 is classified as a critical vulnerability due to the potential for arbitrary code execution by an authenticated user with administrative privileges.
How do I fix CVE-2019-8231?
To resolve CVE-2019-8231, upgrade Magento Open Source to version 1.9.4.3 or later, and Magento Commerce to version 1.14.4.3 or later.
Who is affected by CVE-2019-8231?
CVE-2019-8231 affects all users of Magento Open Source versions prior to 1.9.4.3 and Magento Commerce versions prior to 1.14.4.3.
What types of attacks can CVE-2019-8231 facilitate?
CVE-2019-8231 can allow an authenticated user to execute arbitrary code, potentially leading to full system compromise.
Is authentication required to exploit CVE-2019-8231?
Yes, exploitation of CVE-2019-8231 requires the attacker to have administrative privileges within the Magento platform.