CVE-2019-8120Cross-site Scripting in Magento

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 64.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 5
Latest updateMay 24

Description

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email address.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

NVDmagento/magento2.1.02.1.19+2
Packagistmagento/community-edition2.1.02.1.19+2
CVEListV5adobe_systems_incorporated/magento_2Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p2

Patches

🔴Vulnerability Details

3
GHSA
Magento 2 Community Edition XSS Vulnerability2022-05-24
OSV
Magento 2 Community Edition XSS Vulnerability2022-05-24
CVEList
CVE-2019-8120: A stored cross-site scripting (XSS) vulnerability exists in Magento 22019-11-05
CVE-2019-8120 — Cross-site Scripting in Magento | cvebase