CVE-2019-7867

All FrameworksMagentoCWE-OtherCVE-2019-7867

CVE-2019-7867

State: PUBLISHED · Published: 2019-08-02 · Updated: 2024-08-04 · Assigner: adobe
Description
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to manage orders and order status.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2019/7xxx/CVE-2019-7867.json