CVE-2019-7899Improper Input Validation in Magento

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 81.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDmagento/magento2.1.02.1.18+4
Packagistmagento/community-edition2.1.02.1.18+2

🔴Vulnerability Details

3
OSV
Magento 2 Community Edition Information Disclosure2022-05-24
GHSA
Magento 2 Community Edition Information Disclosure2022-05-24
CVEList
CVE-2019-7899: Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 12019-08-02
CVE-2019-7899 — Improper Input Validation in Magento | cvebase