PT-2019-18886 · Adobe · Magento

Published

2019-11-05

·

Updated

2022-05-24

·

CVE-2019-8110

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Magento 2.2 versions prior to 2.2.10 Magento 2.3 versions prior to 2.3.3 or 2.3.2-p1
Description A remote code execution issue exists, allowing an authenticated user to manipulate the interceptor class via email templates hierarchy. This manipulation enables an attacker to execute arbitrary code.
Recommendations For Magento 2.2 versions prior to 2.2.10, update to version 2.2.10 or later. For Magento 2.3 versions prior to 2.3.3, update to version 2.3.3 or later. For Magento 2.3 version 2.3.2, apply patch 2.3.2-p1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-8110
GHSA-GFCQ-WH3G-C6H4

Affected Products

Magento