ZeroHour

CVE-2019-7888

CVSS 3.0
6.5 medium
EPSS
<1%p59
Published
()
Modified
Description

An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates could leak sensitive data via a malicious email template.

Vendors
magento
Products
magento
Ecosystems
E-commerce
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.