CVE-2019-7851
published 2019-08-02CVE-2019-7851: A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data…
PriorityP426medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
0.44%
35.2th percentile
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from customer pages.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| magento | community-edition | >= 2.1.0 < 2.1.18 | 2.1.18 |
| magento | community-edition | >= 2.2.0 < 2.2.9 | 2.2.9 |
| magento | community-edition | >= 2.3.0 < 2.3.2 | 2.3.2 |
| magento | magento | >= 2.1.0 < 2.1.18 | 2.1.18 |
| magento | magento | >= 2.2.0 < 2.2.9 | 2.2.9 |
| magento | magento | >= 2.3.0 < 2.3.2 | 2.3.2 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
runc-app, runc-stable regression
osv·2025-11-24·CVSS 7.5
CVE-2025-31133 runc-app, runc-stable regression
runc-app, runc-stable regression
USN-7851-1 fixed vulnerabilities in runC. The introduction of a new
upstream release has caused regressions in runc-app and runc-stable.
This update fixes the problem.
Original advisory details:
Lei Wang and Li Fubang discovered that runC incorrectly handled masked
paths. An attacker could possibly replace a container's /dev/null
with a symlink to some other procfs file and possibly escape a container.
(CVE-2025-31133)
Lei Wang and Li Fubang discovered that runC incorrectly handled the
/dev/console bind-mounts. An attacker could potentially exploit this issue
to build-mount a symlink and escape a container. (CVE-2025-52565)
Li Fubang and Tõnis Tiigi discovered that the fix for CVE-2019-16884 was
incomplete. An attacker could possibly use this issue to
OSV
Magento 2 Community Edition CSRF vulnerability
osv·2022-05-24
CVE-2019-7851 [MEDIUM] Magento 2 Community Edition CSRF vulnerability
Magento 2 Community Edition CSRF vulnerability
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from customer pages.
GHSA
Magento 2 Community Edition CSRF vulnerability
ghsa·2022-05-24
CVE-2019-7851 [MEDIUM] CWE-352 Magento 2 Community Edition CSRF vulnerability
Magento 2 Community Edition CSRF vulnerability
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from customer pages.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-02
Published