CVE-2019-7881

MEDIUM

Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Authenticated Cross-Site Scripting

Title source: llm
STIX 2.1

Description

A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0009
EPSS Percentile 24.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
magento/community-edition 2.1 - 2.1.18Packagist
magento/magento 2.1.0 - 2.1.18
Published Aug 02, 2019
Tracked Since Feb 18, 2026