Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This vulnerability could be abused by an authenticated user with the ability to configure the catalog search.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: adobe
Published: 2019-08-02T21:20:53
Updated: 2024-08-04T21:02:19.254Z
Reserved: 2019-02-12T00:00:00
Link: CVE-2019-7885
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-08-02T22:15:16.567
Modified: 2024-11-21T04:48:54.997
Link: CVE-2019-7885
Redhat
No data.