CVE-2019-7892

HIGH

Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Authenticated Remote Code Execution via Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to access shipment settings can execute arbitrary code via server-side request forgery.

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0083
EPSS Percentile 74.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-918
Status published
Products (2)
magento/community-edition 2.1 - 2.1.18Packagist
magento/magento 2.1.0 - 2.1.18
Published Aug 02, 2019
Tracked Since Feb 18, 2026