CVE-2019-7873

MEDIUM

Magento 2.1.0-2.1.17 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of the store design schedule.

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 8.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (2)
magento/community-edition 2.1.0 - 2.1.18Packagist
magento/magento 2.1.0 - 2.1.18
Published Aug 02, 2019
Tracked Since Feb 18, 2026