CVE-2019-7881

All FrameworksMagentoCWE-OtherCVE-2019-7881

CVE-2019-7881

State: PUBLISHED · Published: 2019-08-02 · Updated: 2024-08-04 · Assigner: adobe
Description
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2019/7xxx/CVE-2019-7881.json