CVE-2019-7888

MEDIUM

Magento <2.1.18-2.3.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates could leak sensitive data via a malicious email template.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0011
EPSS Percentile 29.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (2)
magento/community-edition 2.1 - 2.1.18Packagist
magento/magento 2.1.0 - 2.1.18
Published Aug 02, 2019
Tracked Since Feb 18, 2026