CVE-2019-7939

MEDIUM

Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Reflected Cross-Site Scripting on Customer Cart Checkout Page

Title source: llm
STIX 2.1

Description

A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by sending a victim a crafted URL that results in malicious javascript execution in the victim's browser.

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0013
EPSS Percentile 31.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
magento/community-edition 2.1 - 2.1.18Packagist
magento/magento 2.1.0 - 2.1.18
Published Aug 02, 2019
Tracked Since Feb 18, 2026