PT-2019-18879 · Adobe · Magento

Published

2019-11-05

·

Updated

2020-08-24

·

CVE-2019-8091

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Magento 1 versions prior to 1.9.4.3 Magento 1 versions prior to 1.14.4.3
Description A remote code execution issue exists, allowing an authenticated admin user with access to product attributes to trigger remote code execution through layout updates.
Recommendations For versions prior to 1.9.4.3, update to version 1.9.4.3 or later. For versions prior to 1.14.4.3, update to version 1.14.4.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-8091

Affected Products

Magento