CVE-2019-7849

HIGH

Magento <1.9.4.2, <1.14.4.2, <2.1.18, <2.2.9, <2.3.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2, Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-384
Status published
Products (3)
magento/community-edition 2.1.0 - 2.1.18Packagist
magento/magento < 1.14.4.2
magento/magento 1.0.0 - 1.9.4.2
Published Aug 02, 2019
Tracked Since Feb 18, 2026