CVE-2019-8120

MEDIUM

Magento 2.1.0-2.1.18, 2.2.0-2.2.9, 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Customer Email Address

Title source: llm
STIX 2.1

Description

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email address.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0015
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
magento/community-edition 2.1.0 - 2.1.19Packagist
magento/magento 2.1.0 - 2.1.19 (2 CPE variants)
Published Nov 05, 2019
Tracked Since Feb 18, 2026