A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when adding an image for during simple product creation.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1952 A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when adding an image for during simple product creation.
Github GHSA Github GHSA GHSA-29mr-gr4c-vf9c Magento 2 Community Edition XSS Vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-08-04T21:10:32.612Z

Reserved: 2019-02-12T00:00:00

Link: CVE-2019-8115

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-05T23:15:12.087

Modified: 2024-11-21T04:49:18.873

Link: CVE-2019-8115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses