ZeroHour

CVE-2019-8090

CVSS 3.1
6.5 medium
EPSS
<1%p54
Published
()
Modified
Description

An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated users can manipulate the design layout update feature.

Vendors
magento
Products
magento
Ecosystems
E-commerce
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.