ZeroHour

CVE-2019-8229

CVSS 3.1
7.2 high
EPSS
1%p71
Published
()
Modified
Description

In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit product attributes can execute arbitrary code through crafted layout updates.

Vendors
magento
Products
magento
Ecosystems
E-commerce
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.