A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with admin privileges to create or edit a product can execute arbitrary code via malicious XML layout updates.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5433 | A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with admin privileges to create or edit a product can execute arbitrary code via malicious XML layout updates. |
Github GHSA |
GHSA-vvf9-fxhv-4rgj | Magento 2 Community Edition RCE |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-04T21:02:19.368Z
Reserved: 2019-02-12T00:00:00
Link: CVE-2019-7942
No data.
Status : Modified
Published: 2019-08-02T22:15:19.143
Modified: 2024-11-21T04:48:59.370
Link: CVE-2019-7942
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA