CVE-2019-7898

MEDIUM

Magento <1.9.4.2-2.3.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to inadequate validation of user input.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0006
EPSS Percentile 18.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-20
Status published
Products (3)
magento/community-edition 2.1 - 2.1.18Packagist
magento/magento < 1.14.4.2
magento/magento < 1.9.4.2
Published Aug 02, 2019
Tracked Since Feb 18, 2026