CVE-2019-7951

All FrameworksMagentoCWE-OtherCVE-2019-7951

CVE-2019-7951

State: PUBLISHED · Published: 2019-08-02 · Updated: 2024-08-04 · Assigner: adobe
Description
An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A SOAP web service endpoint does not properly enforce parameters related to access control. This could be abused to leak customer information via crafted SOAP requests.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2019/7xxx/CVE-2019-7951.json