CVE-2019-7898Improper Input Validation in Magento

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 81.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to inadequate validation of user input.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDmagento/magento2.1.02.1.18+4
Packagistmagento/community-edition2.12.1.18+2

🔴Vulnerability Details

3
GHSA
Magento 2 Community Edition Information Disclosure2022-05-24
OSV
Magento 2 Community Edition Information Disclosure2022-05-24
CVEList
CVE-2019-7898: Samples of disabled downloadable products are accessible in Magento Open Source prior to 12019-08-02
CVE-2019-7898 — Improper Input Validation in Magento | cvebase