CVE-2019-7935

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

4.8medium3.x
0246810

CVSS Score: 4.8/10

All CVSS Scores

CVSS 3.x
4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CVSS 2.0
3.5

Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Description

A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify content page titles to inject malicious javascript.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-79

Vulnerable Software (1)

Type: Configuration

Vendor: magento

Product: magento

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",      "versionEndExcluding": "1.9.4.2",      "vulnerable": true    },    {      "cpe23uri": "cpe:2...

Source: nvd