CVE-2019-7888Sensitive Information Exposure in Magento

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 70.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates could leak sensitive data via a malicious email template.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDmagento/magento2.1.02.1.18+2
Packagistmagento/community-edition2.12.1.18+2
CVEListV5adobe_systems_incorporated/magento_2Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2

🔴Vulnerability Details

3
GHSA
Magento 2 Community Edition Information Disclosure2022-05-24
OSV
Magento 2 Community Edition Information Disclosure2022-05-24
CVEList
CVE-2019-7888: An information disclosure vulnerability exists in Magento 22019-08-02
CVE-2019-7888 — Sensitive Information Exposure | cvebase