PT-2019-18778 · Adobe · Magento

Published

2019-08-02

·

Updated

2022-05-24

·

CVE-2019-7852

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Magento 2.1 versions prior to 2.1.18 Magento 2.2 versions prior to 2.2.9 Magento 2.3 versions prior to 2.3.2
Description A path disclosure issue exists, where requests for a specific file path could result in a redirect to the URL of the Magento admin panel, potentially disclosing its location to unauthorized parties.
Recommendations For Magento 2.1 versions prior to 2.1.18, update to version 2.1.18 or later. For Magento 2.2 versions prior to 2.2.9, update to version 2.2.9 or later. For Magento 2.3 versions prior to 2.3.2, update to version 2.3.2 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-7852
GHSA-XCGP-C6HP-CJ4R

Affected Products

Magento