PT-2019-18782 · Adobe · Magento

Published

2019-08-02

·

Updated

2022-05-24

·

CVE-2019-7857

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Magento 2.1 versions 2.1.0 through 2.1.17 Magento 2.2 versions 2.2.0 through 2.2.8 Magento 2.3 versions 2.3.0 through 2.3.1
Description A cross-site request forgery issue can cause unwanted items to be added to a shopper's cart due to an insufficiently robust anti-CSRF token implementation.
Recommendations For Magento 2.1 versions 2.1.0 through 2.1.17, update to version 2.1.18 or later. For Magento 2.2 versions 2.2.0 through 2.2.8, update to version 2.2.9 or later. For Magento 2.3 versions 2.3.0 through 2.3.1, update to version 2.3.2 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-7857
GHSA-F6WW-VQW2-XP3V

Affected Products

Magento