CVE-2019-7851

MEDIUM

Magento 2.1.0-2.1.17 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from customer pages.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 8.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-352
Status published
Products (2)
magento/community-edition 2.1.0 - 2.1.18Packagist
magento/magento 2.1.0 - 2.1.18
Published Aug 02, 2019
Tracked Since Feb 18, 2026